Benjamin Sølberg
Benjamin Sølberg
Both 32/64 bit intergers as well as ascii and UTF-16 strings should be supported
Some malware samples validates the names of the parent application and expecting it to be say rundll32.exe or word.exe hence the need to explicit set this name.
To better aid using RunDLL-NG in an automated sandbox. Robust exception handling is a must.
I did some reverse engineering of the firmware a while back: https://github.com/BenjaminSoelberg/danfoss-eco2