What will the VX writer or "hacker" do when trying to bypass the "Signature-Based" Anti-virus program? They will normally "compressed" the executable file using packer tools such as UPX (Ultimate Packer for eXecutables). Tools like UPX will reduce the size of the executable file and will modified the "file signature".I try to test this theory but running UPX on the Netbus trojan.

I uses the UPX to compress Netbus.exe to netbus-upx1.exe



After scanning the NetBus.exe on 32 Anti Virus program. Out of 32 AV, 31 of them detected as NetBus trojan.


- CAT-QuickHeal
- eTrust-Vet
- FileAdvisor
- NOD32v2
- Norman
- Prevxl
- Sunbelt
- TheHacker
- VirusBuster
So u know that some anti virus can be bypassed. As NetBus is a very old and famous tools, many well-known Anti virus vendors had already added the variants. But you can still try to "compressed" other malware to see if they can bypass "signature-based" anti virus programs.

No comments:
Post a Comment