govolution / avet

AntiVirus Evasion Tool
GNU General Public License v3.0
1.65k stars 334 forks source link

All the backdoors are now getting detected by windows defender ? How to solve this issue ? #17

Closed ghost closed 6 years ago

govolution commented 6 years ago

Just tested with ./build/build_win32_meterpreter_rev_https_50xshikata.sh and was not detected, windows 7.

ghost commented 6 years ago

Tested the same template on W10 and DETECTED.

govolution commented 6 years ago

./build/build_win32_meterpreter_rev_https_shikata_loadfile.sh -> worked for me on Windows 10 with defender.

ghost commented 6 years ago

You'r windows defender are update ? Beacause for me ./build/build_win32_meterpreter_rev_https_shikata_loadfile.sh is detected.

Whatever, Can you send all commande what you does for the loadfile build ?

Thanks !!

govolution commented 6 years ago

Of course defender is updated. I never had similar problems. It is all in ./build/build_win32_meterpreter_rev_https_shikata_loadfile.sh, you only need to edit it with your correct ip.

ghost commented 6 years ago

Hi, Yes the ./build/build_win32_meterpreter_rev_https_shikata_loadfile.sh is not detected, But it don't work. he don't try to connect to the attack machine.

they is a difference between the code and the exemple at line 13 ./make_avet -l thepayload.exe -E

govolution commented 6 years ago

I will update the readme soon for the next version. The build script works for me. If a connection does not work it may have several reasons and unfortunetely I can not give support for everything.