Skip to content

A Multi-Pass Encoder & Heuristic Sandbox Bypass AV Evasion Tool!

Latest
Compare
Choose a tag to compare
@An-spectator An-spectator released this 19 Dec 15:18
9549914

The tool is I developed while doing research on anti-virus evasion. It was designed to use simple xor, add, or sub instructions to encode Windows executable files in order to defeat sandbox-based, heuristic run time detections and minimize the static nature of the decoding/heuristic code to combat signature detection. At the time of its development it was relatively successfuly at evading detection from most major AV products (though that may not be the case today).