![]() |
|
File obfuscators that doesn't trigger antivirus software - Printable Version +- Sinisterly (https://sinister.li) +-- Forum: Computers (https://sinister.li/Forum-Computers) +--- Forum: Software & Programs (https://sinister.li/Forum-Software-Programs) +--- Thread: File obfuscators that doesn't trigger antivirus software (/Thread-File-obfuscators-that-doesn-t-trigger-antivirus-software) |
File obfuscators that doesn't trigger antivirus software - Cyb3rNuX - 10-30-2017 I'm software developer and worst thing that can happen to me is my software's source codes to be leaked (which already happened, duh). Currently i'm using ConfuserEx which works fine, but triggers few antiviruses on VirusTotal, but it doesn't contain anything malicious. Is there any other that i can use that won't be detected? Thanks. RE: File obfuscators that doesn't trigger antivirus software - mothered - 10-30-2017 On some occasions (not always), a signed certificate can help with false positive detections- particularly when the application Is requesting an outgoing connection through an open port, thereby the Installed AV may detect It's action as malicious. It's difficult to account for every AV, meaning Installed AVs that are not Included In online scanning engines. The likes of Obsidium, Themida, VMprotect and PELock do the job well but when you're dealing with low-end AVs that flag almost anything as malicious without anything substantiating their claim (signatures, hash etc), It can be a lengthy trial and error process. RE: File obfuscators that doesn't trigger antivirus software - Cyb3rNuX - 10-30-2017 (10-30-2017, 05:19 AM)mothered Wrote: On some occasions (not always), a signed certificate can help with false positive detections- particularly when the application Is requesting an outgoing connection through an open port, thereby the Installed AV may detect It's action as malicious. You mean that i should sign some kind of certificate for as many as possible AV's? That seems boring, duh. Is it good to crypt my software then? RE: File obfuscators that doesn't trigger antivirus software - mothered - 10-30-2017 (10-30-2017, 08:17 PM)Cyb3rNuX Wrote: Is it good to crypt my software then? If you crypt It, as you're aware It will get flagged by a given AV at some point, hence will not remain FUD for the term of the software's existence. RE: File obfuscators that doesn't trigger antivirus software - Cyb3rNuX - 10-31-2017 (10-30-2017, 08:43 PM)mothered Wrote:(10-30-2017, 08:17 PM)Cyb3rNuX Wrote: Is it good to crypt my software then? As i thought so... Well, i guess i should begin searching for some other file obfuscators
RE: File obfuscators that doesn't trigger antivirus software - mothered - 10-31-2017 (10-31-2017, 01:43 PM)Cyb3rNuX Wrote: As i thought so... Well, i guess i should begin searching for some other file obfuscators When I was reverse engineering many years ago (around 10 years), I used Themida a few times which served It's purpose very well. To name only a few benefits, It did a very good job with entry point protection, anti-breakpoint, IT/IAT (Import Table/Import Address Table) reconstruction prevention, however due to It's nature, It was flagged by a few AVs. Not sure If that's the case nowadays, but It's protection was certainly superior. EDIT: Typo. |