How To Make Trojan FUD
Trojans Are detected by Antivirus,So We Need To Make It Undetectable.Below Are Some Methods To Make Trojens FUD (Fully Undetectable)...
http://kingofdkingz99.blogspot.com/2012/01/how-to-make-trojan-fud.html
Trojans
Are detected by Antivirus,So We Need To Make It Undetectable.Below Are
Some Methods To Make Trojens FUD (Fully Undetectable)
1. Encryptors/Compressors:
You
would think this should be the easiest way to UD (Undetect) a
Trojan...but alas, it is not. The problem is simply this, most people
use the same Trojans and Packers so often that Anti-Virus software knows
pretty much all the signatures. They either use Ardamax Keylogger,
Optix Pro, Beast, ProRat etc. for Trojans. For Packers they use UPX,
PECompress, AsPack, Mophine etc. Again, none of these combinations work
because all the signatures have been flagged. The best way this option
will work is to find lesser known Packers and Trojans to work with.
Try a
Google search for Executable Packers. Get a few that you have not heard
of before or that have a decent rating. If it is not freeware, I am
sure there will be a Crack for it. For Trojans, three good resources are
VXChaos, LeetUpload or VX Heaven. Remember to pick the ones that are
not well known and try to mix and match those Trojans and Packers.
2. Byte Adders:
This
technique allows you to add junk bytes to your Trojan as to confuse
Anti-Virus software. It does this by moving the code around inside the
executable as the bytes are being added. This means that the signature
will not be in the place the Anti-Virus expects it to be. A good tool
for this would be StealthTools v2.0 by Gobo.
3. Hex Editing:
This
is much more complicated and takes a lot more practice to get right.
The idea here is to find the signature that Anti-Virus software has
flagged inside of your Trojan and change it by adding a different byte,
or changing the Offset to one of its other equivalents.
The
three things you will need here is a File Splitter, Hex Editor and a
Anti-Virus Offset Finder. The File Splitter will cut your executable
into smaller files (preferably 1 byte per file). You then use your Hex
Editor on the file that holds the signature and change that signature.
Or, you can keep the file complete and use your AV Offset Finder to find
the Offsets automatically and just change the signatures found with
your Hex Editor.
Step One: Place your Trojan Server in a folder.
Step Two:
Split your Server with your File Splitter into 1 byte per file. This
may make a lot of files in your folder (depending on how large the
Server is), but it is worth it because you will know that only one or
two of those files has the signature that is flagged and all the rest
are clean.
Step Three:
Scan your folder with your Anti-Virus software and make note of which
files it says are infected. Those will be the ones you edit.
Step Four:
Open up each infected file with your Hex Editor and change the Offset.
There is no fool proof way of doing this, you will have to experiment.
Since this will be a 1 byte file, there will not be much you need to
change. Just change one character or byte at a time and then save your
progress. Re-scan to see if it worked. If it did not, go back and try
again.
Step Five:
Once you feel that you have found all signatures and changed them,
Rejoin your files with your File Splitter and test your Server to see if
it works. Remember that too much Editing will make your Server useless
so be careful.
Step Six:
Another good way is to use a Anti-Virus Offset Finder that will find
the correct Offset automatically so you do not have to search for them
or split your Server. Get AV Devil 2.1 to find the Offsets (password is:
to0l-base).
You have to remember that different AV software use different signatures, so scan with as many as you can.
Download Hexeditor + file splitter&joiner here
Nice compilation.
ReplyDeleteI published my own list of tools & techniques to avoid AV detection. It covers some of your points and goes beyond them in some points. Maybe you want to check them out:
http://www.shelldaemon.com/2014/09/bypassing-anti-virus-packers-crypters.html
Submit your website or blog now for appearing in Google and over 300 other search engines!
ReplyDeleteOver 200,000 websites submitted!
Submit RIGHT NOW with I Need Hits!!!