#masking the .exe file extension.

115 messages · Page 1 of 1 (latest)

subtle abyss
#

I heard about that right to left trick but it shows .Exe when someone previews the Dropbox link

subtle abyss
#

can someone help me please file extension tools just triggers my anti virus my malware is already undetectable but i think windows defender recognizes that i am trying to change the extension.

noble crater
#

Use .scr

#

Behaves exactly the same way .exe does, but people don't often know that

noble crater
#

If it's an executable it's an executable

#

And it'll be given a scan

subtle abyss
#

Oh

#

Well look at this

#

I did that right to left Unicode thing

#

And it detects it as a malware

#

But my actual malware is undetectable

subtle abyss
#

Hmm

noble crater
#

Yes

#

There are some other extensions which are the same

subtle abyss
#

So there a way I can just injact it in a real photo

#

And it executes when they open it

noble crater
#

Nah don't think so

#

Would require a vulnerability in the image reader

subtle abyss
#

Oh

noble crater
#

That allows for arbitrary code execution

subtle abyss
#

Well this is soo hard because all I need to finish this Projact is to convince that person that it’s a image

#

Because the batch file opens downloads and opens the image

#

As normal

#

And starts the malware

#

Then deletes itself

noble crater
#

batch file

#

Gross

subtle abyss
#

That’s not the malware

#

Tho

#

My malware is shellcode

noble crater
#

I still hate batch

subtle abyss
#

Is there a good

#

One

noble crater
#

Are you "converting" the batch to an executable?

subtle abyss
#

Yes

#

I am

noble crater
#

Just write it in a language that actually compiles lol

subtle abyss
#

I can write it in C

subtle abyss
#

Huh

noble crater
#

Not sure if all of these are clickable to execute

#

But there's a list

subtle abyss
#

They all look suspicious tho

#

I wish there’s a way to just make it say jpg

#

Without triggering the windows defender

noble crater
#

.scr is the best you're gonna get

#

It's still pretty good

noble crater
subtle abyss
#

Well is there a way for a Exe to execute open extraction form a zip

subtle abyss
#

Is written in C

#

Lol

noble crater
#

When you say shellcode

#

You mean reverse shell

#

Right?

subtle abyss
#

No

#

C2

#

Framework I made

#

Custom

noble crater
#

A C2 is a server

subtle abyss
#

Yes

#

More then one connection

#

Can connect

noble crater
#

So the client program that connects to the C2 is what you're talking about, right?

subtle abyss
#

I have no problem with my actual malware my problem is that if the target sees the file as .Exe

#

Or any other

#

He will think it’s a virus

#

So I am thinking of a way

noble crater
#

I'm just asking because I'm interested mainly

subtle abyss
#

To hack him before he realizes

#

Yea

noble crater
#

When people talk about shellcode they're talking about asm-level stuff quite often

#

Tiny bits of assembly code which get hidden away in a program

subtle abyss
#

Yes

#

That

#

But I want her to click on the image

#

😢

noble crater
#

I'm guessing you've probably got some metasploit thingy or whatever

subtle abyss
#

Nah

noble crater
#

Idk I don't use tools, more fun from scratch

subtle abyss
#

Yea mine is custom

#

I am not using a tool

#

That’s why my malware is hard to detect

#

It also installs malware in the bios

#

When executed

#

But I have a question is there a way for my malware to run upon extraction from a zip

noble crater
#

I don't know of any way of doing that

subtle abyss
#

Ok thank you tho man

#

I will figure it out

#

I made like 50 scripts trying to change it I thought it wouldn’t be this hard to mask a extension😢

noble crater
#

Maybe there's a different way of getting whoever to run the file

#

Idk what the context is so I can't come up with anything useful

subtle abyss
#

Oh hey I was able to make it .jpg

#

Without AV

#

Detecting it

#

But there is one problem sometimes it’s very rare

#

But my friend keeps making a big deal out of it

#

The pop

#

Up that says publisher unknown

#

It doesn’t happen often right?

#

Because for me it only happened once

#

After many clicks and the computer was already infected

#

The vm.

#

Is there a way to find fake CA’s

#

Because he wants the malware to be 100% undetected

noble crater
subtle abyss
#

Ohh thank you soo much man

void gull
#

seems like your code itself is getting caught not the extension though

#

what sort of encoding are you using?

subtle abyss
#

i am using aes and base64

#

my code is not getting caught... without it, its totally fine.

#

only 1 detection