Update README.md

This commit is contained in:
S3N4T0R
2024-12-08 23:01:43 -05:00
committed by GitHub
parent c8e96e134a
commit fe25c57595
+1 -1
View File
@@ -12,7 +12,7 @@ This attack included several stages including DodgeBox, a reflective DLL loader
![imageedit_2_3915351931](https://github.com/user-attachments/assets/1ddd642e-4cd1-4bb5-bfc1-6a8e342d6364)
1. Employs DLL sideloading as a means of executing DodgeBox.
1. Employs DLL sideloading as a means of executing DodgeBox. employs DLL sideloading as a means of executing DodgeBox. They utilize a legitimate executable (taskhost.exe).
2. The malicious DLL, DodgeBox, serves as a loader and is responsible for decrypting a second stage payload from an encrypted DAT file (sbiedll.dat), The decrypted payload, MoonWalk functions as a backdoor.