bytecode77/r77-rootkit
Fileless ring 3 rootkit with installer and persistence that hides processes, files, network connections, etc.
CBSD-2-Clause
Issues
- 2
- 5
somehting bug me for days(not r77 bug)
#107 opened by wineggdrop - 4
GetProcessFileName() issue
#105 opened by wineggdrop - 2
What are these ip's used for?
#106 opened by VibeProgramm - 4
NtQueryDirectoryFile
#100 opened by MaggieKong - 4
A bug In HookedNtQueryDirectoryFile
#104 opened by wineggdrop - 1
- 8
$77 is showed in windows defender execlude
#102 opened by SkynetCorporations - 8
question
#101 opened by charlesmigel - 2
Unknown Issue
#99 opened by MaggieKong - 20
Hiding users (net.exe and lusrmgr.msc)
#74 opened by MaggieKong - 1
- 1
File.Exists or Directory.Exists still return true
#98 opened by mrapxs - 1
- 12
This script contains malicious content and has been blocked by your antivirus software.
#94 opened by error0x1337 - 1
22:14:14 Injection of (process) (PID [REDACTED[) failed. Sandboxes are not supported
#89 opened by PROMPTYLOL - 2
Help
#88 opened by PROMPTYLOL - 2
Unable to hide netstat network connections
#95 opened by badboycxcc - 2
try to make it FUD
#93 opened by charlesmigel - 11
file not found: Resources\Stager.exe
#92 opened by error0x1337 - 1
rebuild issues
#91 opened by SkynetCorporations - 7
HookedNtEnumerateKey CPU Overhead??
#90 opened by mrapxs - 1
- 2
Detect $77 process in python ?
#86 opened by Evaexe117 - 0
Question.
#85 opened by ConstantLearner121 - 2
(0xc0000005) 'Access violation'
#84 opened by mrapxs - 4
[ HELP ] — How I can use the ControlPipe in C# ?? 🥴
#82 opened by fSociety-Protected - 7
Add Support for The Use of WildCard Characters
#83 opened by Chainski - 10
I discovered new rootkit vulnerability stronger than your rootkit with 0 coding (no admin required)
#75 opened by GrudgeInfection - 3
Install.shellcode
#79 opened by sa6ta6ni6c - 8
r77 pipes
#80 opened by hastalamuerte - 3
Help
#72 opened by MazenNassar - 11
- 2
Significant challenge with BitDefender AV (BD) that affects the operation of admin-level processes
#77 opened by Ogyeet10 - 4
- 5
testconsole won't work
#73 opened by MaggieKong - 1
Help Needed - Happy to pay consulting fees
#71 opened by Totalnoob1164 - 3
ControlPipe using Powershell
#70 opened by APT-ZERO - 11
how to change perfix $77 to my own keyword
#62 opened by DARK-DEVIL-66 - 6
Adding a .exe to startup
#68 opened by Klaped - 7
How to use shellcode?
#61 opened by Summ3rM0 - 0
r77 rookit injects into PROCESS_CREATION_MITIGATION_POLICY_BLOCK_NON_MICROSOFT_BINARIES_ALWAYS_ON process
#67 opened by wineggdrop - 4
"MSB3073" Error
#66 opened by jsk6 - 5
Teaching lessons
#64 opened by jsk6 - 1
Contact information
#65 opened by Knakiri - 2
- 1
Removal tool
#57 opened by pyluadotcode - 2
$77 How can a non-interactive SYSTEM permission process use ShellExecuteW so that its child processes can be interactive
#55 opened by saoye-dve - 7
- 7