Modifying Metasploit x64 template for AV evasion
ID: 36e2a63a-9732-5a27-b223-744c2ad79b47
STIX ID: report--36e2a63a-9732-5a27-b223-744c2ad79b47
Feed Name: Black Hills Infosec Blog
Threat Score
This blog post describes experiments modifying Metasploit's 64-bit PE template to evade Avast antivirus: the default template is detected, but simple assembly changes (such as increasing the payload buffer) caused Avast to miss the payloads and allowed successful remote shell execution. The author concludes that some AV engines match template assembly rather than payload shellcode and plans to repeat tests across other AV products.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
