Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 43 guests online
EH-Net News Feeds
Latest Additions
 
Advertisement

You are here: Home arrow Forum arrow Ethical Hacking Discussions and Related Certificationsarrow Malwarearrow need a help in hiding a trojan
EH-Net
May 24, 2012, 03:38:03 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Advertise on EH-Net!! - Reasonable Rates, Highly Targeted Audience.
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: need a help in hiding a trojan  (Read 5160 times)
0 Members and 2 Guests are viewing this topic.
jaxverts
Newbie
*
Offline Offline

Posts: 3


View Profile
« on: May 03, 2007, 06:23:02 AM »

hello don..
   i m a CEH .. & was having a little work around .. i was trying to edit my bind.exe but it get detected by my nt virus i user MCafee .. i belive that ntvirus just have signature to block them can u help me where can i find detail for such signature ..
 i tryed editing those bind.exe but once i do it i get some error & program dont run.. i tryed wraping with elitewrape & few other tools but still it get detected..
  can u help me with this..

regards
jax
Logged
BillV
Hero Member
*****
Offline Offline

Posts: 1830


View Profile WWW
« Reply #1 on: May 03, 2007, 07:34:53 AM »

I'm not quite sure what bind.exe is, but it sounds like you're already trying to bind the trojan to another file. Look for something called Stealth Tools (I think). It will allow you to add size to the exe, manipulate the signature, and a couple of other things. When used properly, it should be able to bypass AV signature checking.
Logged
jaxverts
Newbie
*
Offline Offline

Posts: 3


View Profile
« Reply #2 on: May 03, 2007, 07:57:51 AM »

i have tried Stealth Tools also when i made this bind.exe.  i even added couple of Kbytes but it don't work i converted in VBS (executable)  but still it stop me ..
  bind.exe is a code like nc it allow u to bind any port with any application like 80 port to cmd.exe etc but we don't need to type those command like we do in nc. it was new code still it was detected .. if anybody know how to bypass with ntvirus test ..
Logged
Craig
EH-Net Columnist
Jr. Member
*****
Offline Offline

Posts: 69


View Profile WWW
« Reply #3 on: May 03, 2007, 08:19:58 AM »

From what I know of it, elitewrap is just like a self-extracting ZIP, so once you run it, it will extract the torjan and try to execute the trojan, but once extracted the trojan is un-modified so AV will still pick it up. It is also easy for AV's to add signatures for trojans wrapped by popular packers (UPX, ASPack, etc).

If you want to manually change the AV signature (the best way to do it IMHO), you can't randomly modify data in an executable; you have to either find some bytes in the signature that aren't valid executable data (i.e., 0xCC, 0x00, etc.) or if you have some assembly knowledge you can change the actual instructions without changing the functionality of the program. Of course you first have to find the signature which is pretty easy, it just requires a hex editor and some trial and error. I actually wrote a short tutorial on modifying AV signatures a while back, it's at http://www.craigheffner.com/security/Taking_Back_Netcat.pdf if interested. I also have a couple variations of netcat on my site, one with a modified AV signature and another that reads commands from a text file rather than from the command line which might help you out.

Of course this is all assuming that the anti-virus you are testing against uses signature-based detection (most do). If it uses heuristics-based detection, it may be more difficult to bypass.
Logged

oleDB
Recruiters
Full Member
*
Offline Offline

Posts: 236



View Profile WWW
« Reply #4 on: May 03, 2007, 01:26:55 PM »

Sounds like he is using McAfee, and the OnDemand scanner will use heuristics to detect stuff. You can disable the OnDemand Scanner, but a better option is just to add that file to the exception list. What I do is create a whole folder that is excluded from the scanner to keep tools and malware in.
Logged
dean
Guest
« Reply #5 on: May 03, 2007, 04:32:06 PM »

Try some of the hiders/binders on this list.

http://www.tenebril.com/src/spyware/file-hiders.php

YAB is my personal favorite.

hth,
-dean-
Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.246 seconds with 21 queries.
 

gk_static-ad_feb2012.jpg
Global Knowledge: Build Security Skills to Protect & Defend

els_130x200fixed2.gif
eLearnSecurity Student Course Now Live!
5% Off with Code
ELS-EH-5

SANS Deals 4 EH-Netters
$150 OFF Any SANS Course in Any Format!
Coupon Code: EHN_Connect Including SANS Security West 2012 & SANSFIRE 2012
Recent Forum Topics

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!

Vote For EH-Net

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2012 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.