The power of combining several antivirus bypass techniques
It is important to note that, practically speaking, in order to perform bypassing on an antivirus engine in the real world, you must use a combination of multiple bypass techniques, not just a single one. Even if a specific technique manages to get past a static engine, it is reasonable to assume that a dynamic and/or heuristic engine will be able to detect the file. For example, we can use a combination of the following techniques to achieve a full antivirus bypass:
To demonstrate the concept of combining several antivirus bypass techniques, we will use an amazing Python script named peCloak.py
developed by Mike Czumak, T_V3rn1x
, and SecuritySift
. This tool, as defined by the developers, is a Multi-Pass Encoder & Heuristic Sandbox Bypass AV Evasion Tool that literally combines several antivirus...