Unlimited WordPress themes, plugins & video downloads!

Research

Research – Taking_Back_Netcat.pdf

While there are some easy ways of changing the antivirus signature of a program (packers, encryptors, etc), they may not always be viable options for those wishing to bypass antivirus applications. This paper will show how to locate the signature used to identify Netcat, and modify it so that the executable no longer matches Symantec’s AV signature, without interfering with any of the program’s functionality. This is an exercise in identifying and modifying sections of code (aka, signatures) that are used by antivirus programs to identify malicious code; the tools and techniques used here can be applied to any program that is marked as malicious by AV applications.

 

You can download it from the following link: https://packetstormsecurity.com/files/download/49740/Taking_Back_Netcat.pdf

Source: https://packetstormsecurity.com/files/49740/Taking_Back_Netcat.pdf.html

Related posts
Research

Research - RiseCON 2014 Call For Papers

Research

Research - Rooted CON 2012 Call For Papers

Research

Research - RSA Asymmetric Polymorphic Shellcode

Research

Research - RVAsec 2017 Call For Papers

Sign up for our Newsletter and
stay informed