The exploit code worked well on an XP SP2 machine with no antivirus software, and would work well on any machine that didn't have AV installed, but it was less effective on a Windows 10 machine with the basic default Windows antivirus installed. We had to turn off the real-time checking feature on the antivirus to get the email to read without errors, and the antivirus scrubbed out our doctored file. As security engineers, we are happy that Microsoft Windows 10 has such an effective anti-malware feature, right out of the gate. As penetration testers, we are disappointed.
Backdoor Factory inserts shellcode into working EXE files without otherwise changing the original all that much. You can use the executables in the /usr/share/windows-binaries directory, as shown in the following screenshot, or any other Windows binary that does not...