<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Dll-Hijacking on Journal of Connar</title><link>https://connar.github.io/tags/dll-hijacking/</link><description>Recent content in Dll-Hijacking on Journal of Connar</description><generator>Hugo -- 0.147.3</generator><language>en-us</language><atom:link href="https://connar.github.io/tags/dll-hijacking/index.xml" rel="self" type="application/rss+xml"/><item><title>DLL Hijacking journey</title><link>https://connar.github.io/posts/dll-hijacking-journey/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://connar.github.io/posts/dll-hijacking-journey/</guid><description>&lt;h1 id="a-journey-into-dll-hijacking---hunting-my-own-signed-binary">A journey into DLL Hijacking - Hunting my own signed binary&lt;/h1>
&lt;h2 id="1-where-this-started">1. Where this started&lt;/h2>
&lt;p>There was a point in the past where me and my friend &lt;code>@r4sti&lt;/code> wanted to dig into inno installers and how they could be abused in malware campaigns (&lt;em>perhaps a future post about it&lt;/em>). Unfortunately, he had to go afk for a while, and thus I started researching on the topic. This is when I came across a &lt;a href="https://www.splunk.com/en_us/blog/security/inno-setup-malware-redline-stealer-campaign.html">Splunk threat research writeup&lt;/a> on a RedLine Stealer campaign delivered through a trojanized Inno Setup installer, and I started reading it to learn how the installer itself was being weaponized.&lt;/p></description></item></channel></rss>