Tagged: 

Viewing 4 posts - 1 through 4 (of 4 total)
  • Author
    Posts
  • #40708
    Akabueze
    Participant

    Hello, please why is it I get conflicting results when I scan with with or anitscan.me and virscan.org. Some results are clean in one but are infected in the next one. This is after use HEX tool. Also what other tool like hex because scan on a antiscan.me is detecting up to 10 even after hex edit.

    #40719
    Diego PérezDiego Pérez
    Participant

    Hi Akabueze!
    Basically bypassing AV programs is like a game of cat and mouse, so backdoors might start getting detected at some stage, then the developers release an update, this will allow you to generate undetectable backdoors, then AV programs release an update which will make backdoors detectable ……..

    So the main thing is to make sure that Veil or any other tool you’re using to generate the backdoor is up to date.​​

    Here’s a few solutions to try if your backdoor is getting detected:

    1. Make sure that you have the latest version of Veil, so do ​updated ​before doing ​use 1.

    ​2. Experiment with different payloads, and experiment with different payload options and you should be able to bypass it.​

    3. Try generating a backdoor using the fat rat, empire.

    4. Modify backdoor code if its in bat as shown in lecture 33.

    5. Modify backdoor using a hex editor as shown in lecture 40.

    6. Create your own backdoor (covered in python course).

    The best thing to do is look at the last lecture of the course (bonus lecture) it contains all the courses that you can take with this course and a comparison between them.
    Hope it helps!
    Diego

    #40722
    Akabueze
    Participant

    Is the zloggers and Lazagne that I have this problem with.

    #40779
    Diego PérezDiego Pérez
    Participant

    Hi!
    Then you’ll need to stick to point 5 as you have the executables already.

    Let me know how it goes!
    Diego

Viewing 4 posts - 1 through 4 (of 4 total)
  • You must be logged in to reply to this topic.
Privacy Overview
ZSecurity logo featuring a stylized red letter Z

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Strictly Necessary Cookies

Strictly Necessary Cookie should be enabled at all times so that we can save your preferences for cookie settings.

3rd Party Cookies

This website uses Google Analytics and Linkedin to collect anonymous information such as the number of visitors to the site, and the most popular pages.

Keeping these cookies enabled helps us to improve our website.