sRDI
Aliases: DAVESHELL
- Malware type
- loader
- Family
- Malware family
- Profile updated
- 2026-07-07 13:14:08
Context
sRDI allows for the conversion of DLL files to position independent shellcode. It attempts to be a fully functional PE loader supporting proper section permissions, TLS callbacks, and sanity checks. It can be thought of as a shellcode PE loader strapped to a packed DLL.
Reports & references
- cloud.google.com — Unc4393 Goes Gently Into Silentnight (report)
- Mandiant — Dprk Whatsapp Phishing (report)
- Mandiant — Apt29 Evolving Diplomatic Phishing (report)
- ESET — Lazarus Luring Employees Trojanized Coding Challenges Case Spanish Aerospace Company (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Srdi (report)
- github.com — Srdi (report)