Posts

Showing posts with the label Antivirus

Armor - Tool Designed To Practise Encrypted Macos Payloads Capable Of Evading Antivirus Scanners

Image
Armor is a unproblematic Bash script designed to exercise encrypted macOS payloads capable of evading antivirus scanners. Below is an example gif of Armor existence used alongside a unproblematic Netcat payload. H5N1 Netcat listener is started on port 4444. The "payload.txt" file is read in addition to shown to incorporate a unproblematic Bash one-liner that, when executed, volition exercise a TCP connector betwixt the target MacBook at the attacker's Netcat listener. Armor is used to encrypt the bash one-liner. Ncat is used to host the decryption cardinal on the attacker's server. When the stager is executed inward the target MacBook (not shown inward the gif), the bash one-liner is decrypted in addition to executed without writing whatever information to the harddrive. Ncat at nowadays terminates the listener afterwards the cardinal has been used. When the Netcat connector is established, the assailant has remote access to the target MacBook. Admittedl...

Veil - Tool To Generate Metasploit Payloads That Bypass Mutual Anti-Virus Solutions

Image
Veil is a tool designed to generate metasploit payloads that bypass mutual anti-virus solutions. Veil is electrical flow nether back upwards past times @ChrisTruncer Software Requirements: The next OSs are officially supported: Debian 8+ Kali Linux Rolling 2018.1+ The next OSs are probable able to run Veil: Arch Linux BlackArch Linux Deepin 15+ Elementary Fedora 22+ Linux Mint Parrot Security Ubuntu 15.10+ Setup Kali's Quick Install apt -y install veil /usr/share/veil/config/setup.sh --force --silent Git's Quick Install NOTE : Installation must endure done amongst superuser privileges. If yous are non using the root concern human relationship (as default amongst Kali Linux), prepend commands amongst sudo or alter to the root user earlier beginning. Your bundle manager may endure unlike to apt . sudo apt-get -y install git git clone https://github.com/Veil-Framework/Veil.git cd Veil/ ./config/setup.sh --force --silent ./config/setup.sh /...

Malice - Virustotal Wanna Move (Now Alongside 100% To A Greater Extent Than Hipster)

Image
Malice's mission is to live a costless opened upwards source version of VirusTotal that anyone tin give notice role at whatever scale from an independent researcher to a fortune 500 company. Try It Out DEMO: demo.malice.io username : malice password : ecilam Requirements Hardware 16GB disk space 4GB RAM Software Docker Getting Started (OSX) Install $ brew install maliceio/tap/malice Usage: malice [OPTIONS] COMMAND [arg...] Open Source Malware Analysis Framework Version: 0.3.11 Author: blacktop - <https://github.com/blacktop> Options: --debug, -D Enable debug trend [$MALICE_DEBUG] --help, -h demo assistance --version, -v impress the version Commands: scan Scan a file lookout Watch a folder lookup Look upwards a file hash elk Start an ELK docker container plugin List, Install or Remove Plugins assistance Shows a listing of commands or assistance for i ascendancy Run ...

Phpmussel - Php-Based Anti-Virus Anti-Trojan Anti-Malware Solution

Image
phpMussel is an ideal solution for shared hosting environments, where it's oft non possible to utilize or install conventional anti-virus protection solutions, phpMussel is a PHP script designed to detect trojans, viruses, malware in addition to other threats inside files uploaded to your organization wherever the script is hooked, based on the signatures of ClamAV in addition to others. For information regarding HOW TO INSTALL {2A+2B} in addition to HOW TO USE {3A+3B} phpMussel, delight refer either to the Wiki or to the documentation included inside the " _docs " directory of this repository (direct links to that documentation included nether the "Documentation" header below this paragraph). Features: Licensed every bit GNU General Public License version 2.0 (GPLv2). Easy to install, tardily to customise, tardily to use. Works for whatsoever organization amongst PHP+PCRE installed, regardless of OS (PHP+PCRE required). Fully configurable ba...

Chaos Framework V3.0 - Generate Payloads As Well As Command Remote Windows Systems

Image
CHAOS is a PoC that allow generate payloads as well as command remote operating systems. Features Feature Windows Mac Linux Reverse Shell X X X Download File X X X Upload File X X X Screenshot X X X Keylogger X Persistence X Open URL X X X Get OS Info X X X Fork Bomb X X X Run Hidden X Tested On Kali Linux - ROLLING EDITION How to Install # Install dependencies $ sudo apt install golang git -y # Get this repository $ instruct start github.com/tiagorlampert/CHAOS # Get external golang dependencies (ARE REQUIRED GET ALL DEPENDENCIES) $ instruct start github.com/kbinani/screenshot $ instruct start github.com/lxn/win $ instruct start github.com/matishsiao/goInfo $ instruct start golang.org/x/sys/windows # Maybe y'all volition come across the message "package github.com/lxn/win: construct constraints exclude all Go files". # It's occu...

Ghostdelivery - This Tool Creates A Obfuscated .Vbs Script To Download A Payload Hosted On A Server To %Temp% Directory, Execute Payload Too Make Persistence

Image
Python script to generate obfuscated .vbs script that delivers payload amongst persistence in addition to windows antivirus disabling functions. Features: Downloads payload to TEMP directory in addition to executes payload to bypass windows smart screen. Disables Defender, UAC/user trouble organisation human relationship control, Defender Notifications, injects/creates Command Prompt in addition to Microsoft Edge shortcuts amongst payload path (%TEMP%/payload.exe), adds a scheduled chore called "WindowsDefender" for payload to hold upward run at login in addition to obfuscates the vbs delivery script. This tool also has a serveo business office to deliver obfuscated vbs script. Light version: The low-cal version is less noisy in addition to exclusively delivers/executes payload, creates a scheduled chore named "WindowsDefender" to run payload at login for persistence in addition to injects/creates Command Prompt in addition to Microsoft Edge shortc...