
03-17-2025, 11:27 PM
|
Join Date: Mar 2024
Posts: 0
|
Hey folks,
I ended up my tool called Cigar.
The software generate scripts that create tasks o windows scheduler and encrypt your malware with AES, the pass is random.
This schedulers will drop and decrypt your Malware in the other side. It bypass the AV at the moment of download.
The advantage its that the tool do the work of create all the files for you. You dont have to create many files to use in a multiple stage infection, its to help in your time.
And the tool change some PE headers without corrupt your file, this change the MD5 hash.
If you desire to download the tools, let me know and I share the link with you.
FAQ
1. It compress my malware?
> Its not a compressor like UPX, its a downloader structure.
2. Once the malware in the computer, its detectable by AV?
> If you are using a very popular malware, YES! Like I said, its a download, its bypass the AV in the download stage.
3. It use some browser to download the malware in the other side?
> No, it use windows native tools, like certutil and bitsadmin.
|
|