vysecurity / morphHTA

morphHTA - Morphing Cobalt Strike's evil.HTA
517 stars 130 forks source link

Kaspersky detect this!! #1

Closed ghost closed 7 years ago

ghost commented 7 years ago

hi ,first thanks for this great tool, but kaspersky total security 2017 detect the morphed HTA files, can reFUD your tool please,thanks

vysecurity commented 7 years ago

Ah interesting. Must be because they took my sample from VT :) but I don't think I care enough to change the tool for just 1 vendor. I manually change all my payloads after generation anyways - and so should you. It's only meant to assist :)

vysecurity commented 7 years ago

Maybe in the future