Hackers No Hashing: Randomizing API Hashes to Evade Cobalt Strike Shellcode Detection | Huntress
ID: 35993527-ca26-59c6-9df0-518e423cfcae
STIX ID: report--35993527-ca26-59c6-9df0-518e423cfcae
Feed Name: Huntress Blog
Threat Score
This research post analyzes API-hashing techniques used by Metasploit and Cobalt Strike, shows that many vendors rely on default ROR13 hashes for detection, and demonstrates how altering the rotation value (e.g., to ROR15) and small shellcode tweaks can bypass most detections; the authors provide an automated script to generate modified shellcode and a YARA rule that targets the hashing routine itself to improve detection resilience.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
