screetsec / TheFatRat

Thefatrat a massive exploiting tool : Easy tool to generate backdoor and easy tool to post exploitation attack like browser attack and etc . This tool compiles a malware with popular payload and then the compiled malware can be execute on windows, android, mac . The malware that created with this tool also have an ability to bypass most AV software protection .
GNU General Public License v3.0
9.45k stars 2.26k forks source link

The payload is detectable #573

Closed zisis912 closed 2 years ago

zisis912 commented 3 years ago

I tried making a fud backdoor with PwnWinds, then picked 1 for bat file + powershell, but when i run the powershell script on my windows machine, it says that it is malicious and has been blocked from running. The only av i have is windows defender, which i have set to make an exception on the entire C:/ drive because it annoys me. image Also, I know this has nothing to do with fatrat, but when i try to use a port under 1024 msfconsole says permission denied, even if I have done sudo msfconsole, so if anyone knows a way to set the port to 80 tell me

peterpt commented 3 years ago

meterpreter/reversehttp = port80 or 8080 meterpreter/reversehttps = port 443 or 8443

zisis912 commented 3 years ago

oh ok, but can you help me with my actual problem?

peterpt commented 3 years ago

no , you can thank all other users from before for your payload be detected . It looks that even if we create a banner in the tool to not upload the backdoors to virus total , many users from before did just that just to see if they were detected . After that point virus total was able to analyze the mutex of the backdoors created by fatrat and add them to their database witch is also shared with many other antivirus platforms .

WongWai95 commented 3 years ago

Yes, it is inevitable. Thx for yr repository anyway.

Morsmalleo commented 3 years ago

@peterpt I have tested the payloads built with Powerstager, and Windows 10 virus protection doesn't detect it, so there's a bit of positive for TheFatRat being completely FUD, still yet to test payloads built with PwnWinds

robin113x commented 3 years ago

use own python tools for creating payloads or use veil evsions payloads..