logo

Three Simple Disguises for Evading Antivirus

ID: 63175448-01ad-5056-aed4-6e76c89721a7

STIX ID: report--63175448-01ad-5056-aed4-6e76c89721a7

Feed Name: Black Hills Infosec Blog

Date Published: 2016-07-07

Date Updated: 2026-04-27

Author: BHIS

...
...

The post argues traditional antivirus is largely ineffective against modular payloads like Meterpreter and demonstrates AV-evasion techniques: using 64-bit stagers, replacing MSFVenom’s default PE templates with custom executables or hand-rolled loaders, and optionally encoding shellcode. It generates multiple stager variants (reverse_tcp/http/https), tests them on VirusTotal, and finds that custom templates and 64-bit builds significantly reduce detections—sometimes evading all tested engines—highlighting the need for defenders to go beyond signature-based AV.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.