Skip to content

Malware

sRDI

aka DAVESHELL

sRDI allows for the conversion of DLL files to position independent shellcode.

sRDI allows for the conversion of DLL files to position independent shellcode. It attempts to be a fully functional PE loader supporting proper section permissions, TLS callbacks, and sanity checks. It can be thought of as a shellcode PE loader strapped to a packed DLL.


Family metadata imported from Malpedia (Fraunhofer FKIE).