EndPointCorp / end-point-blog

End Point Dev blog
https://www.endpointdev.com/blog/
17 stars 65 forks source link

Comments for Evading Anti-Virus Detection with Metasploit #753

Open phinjensen opened 6 years ago

phinjensen commented 6 years ago

Comments for https://www.endpointdev.com/blog/2013/01/evading-anti-virus-metasploit/ By Brian Buchalter

To enter a comment:

  1. Log in to GitHub
  2. Leave a comment on this issue.
phinjensen commented 6 years ago
original author: Muhammad Najmi Ahmad Zabidi
date: 2015-12-25T09:20:42-05:00

Elizabeth,

Yeah, anti virus providers usually have some kind of automation, but they do work with static analysis tools as well (for example, hexdump, IDAPro) in order to decompile the malware. You're right it'll take days if to get the anti virus signature updated. In the recent malware development somehow it'll be going to be troublesome if one was infected with ransomware as the attacker usually demand for monies to be transferred via Bitcoin.