Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Detected By AV (Kaspersky, Avira) #11

Open
uxeer opened this issue Jun 26, 2019 · 8 comments
Open

Detected By AV (Kaspersky, Avira) #11

uxeer opened this issue Jun 26, 2019 · 8 comments

Comments

@uxeer
Copy link

uxeer commented Jun 26, 2019

No description provided.

@Ch0pin
Copy link
Owner

Ch0pin commented Jun 26, 2019

Static scan or during execution?
Can you please also provide some details about which technique you used

@uxeer
Copy link
Author

uxeer commented Jun 26, 2019

Without scan or execution, i just copy payload.exe on target PC kaspersky detected it.

@Ch0pin
Copy link
Owner

Ch0pin commented Jun 26, 2019

What injection method did you use?

@uxeer
Copy link
Author

uxeer commented Jun 26, 2019

Thread Hijacking (Shellcode Arch: x86, OS arch: x86)

@Ch0pin
Copy link
Owner

Ch0pin commented Jun 27, 2019

Thank you for your feedback I' ll check and get back to you

@Ch0pin
Copy link
Owner

Ch0pin commented Jun 30, 2019

checked your claim and it is true, I will issue a relative update to solve the issue.
Thanks again for the feedback

@uxeer
Copy link
Author

uxeer commented Jun 30, 2019

Thank you 😀

@Ch0pin
Copy link
Owner

Ch0pin commented Oct 17, 2019

It has been reported that the produced backdoor is no more undetectable from the majority of the AV solutions, which is indeed true and which is something I expected by the time that the software is getting more and more 'popular'. As a temporary solution I advise you to use a C# obfuscator on the produced executable. In my case, I used babel for net (http://www.babelfor.net/) with a great success for the majority of AV’s (including Kaspersky, Avast etc.).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants