Ch0pin/AVIator

Detected By AV (Kaspersky, Avira)

uxeer opened this issue · 8 comments

uxeer commented
Detected By AV (Kaspersky, Avira)

Static scan or during execution?
Can you please also provide some details about which technique you used

uxeer commented

Without scan or execution, i just copy payload.exe on target PC kaspersky detected it.

What injection method did you use?

uxeer commented

Thread Hijacking (Shellcode Arch: x86, OS arch: x86)

Thank you for your feedback I' ll check and get back to you

checked your claim and it is true, I will issue a relative update to solve the issue.
Thanks again for the feedback

uxeer commented

Thank you 😀

It has been reported that the produced backdoor is no more undetectable from the majority of the AV solutions, which is indeed true and which is something I expected by the time that the software is getting more and more 'popular'. As a temporary solution I advise you to use a C# obfuscator on the produced executable. In my case, I used babel for net (http://www.babelfor.net/) with a great success for the majority of AV’s (including Kaspersky, Avast etc.).