klezVirus / inceptor

Template-Driven AV/EDR Evasion Framework
Other
1.6k stars 262 forks source link

Bug Dinvoke Amsi #7

Closed Mantraufo closed 3 years ago

Mantraufo commented 3 years ago

python inceptor.py dotnet -t donut client.exe -o kiwi.exe --sgn --sign --delay 120 -m dinvoke -m amsi

[*] Multiple compatible templates identified, choose one: 0: bypass-dinvoke.cs 1: bypass-dinvoke_manual_mapping.cs $> 0 Traceback (most recent call last): File "C:\Users\LENOVO\Documents\NoteMalware\inceptor\inceptor\engine\modules\AmsiModule.py", line 62, in init kwargs["template"] = self.generate(kwargs=kwargs) File "C:\Users\LENOVO\Documents\NoteMalware\inceptor\inceptor\engine\modules\AmsiModule.py", line 99, in generate template.process_modules() File "C:\Users\LENOVO\Documents\NoteMalware\inceptor\inceptor\engine\Template.py", line 76, in process_modules self.libraries += module.libraries AttributeError: 'NoneType' object has no attribute 'libraries' [-] Exception building AmsiModule

klezVirus commented 3 years ago

Hi Mantraufo, thanks for pointing that out, it was an issue with the architecture which is now required for Dinvoke. Fixed in cf0f9fd.