• XSS.stack #1 – первый литературный журнал от юзеров форума

Macros FUD at ScanTime but gets caught up at RunTime.

jose101

ripper
КИДАЛА
Регистрация
26.05.2022
Сообщения
57
Реакции
7
Депозит
0.0003
Пожалуйста, обратите внимание, что пользователь заблокирован
Hello guys, so i have been trying s.pam this past days but my Macros is getting caught up at RunTime by updated WD..... Anyone has a special ofcuscation method to use on Macros to bypass WD at RunTime ? Willing to pay for info to solve this matter.... TG = ggho5t
 

Вложения

  • Screen Shot 2022-06-27 at 07.25.21.png
    Screen Shot 2022-06-27 at 07.25.21.png
    123.9 КБ · Просмотры: 74
Пожалуйста, обратите внимание, что пользователь заблокирован
You got caught by AMSI, how do you run your payload - ActiveX/Winapi?
ActiveX as usual... if you can find a solution to bypass that popup then we can agree to an amount
 
Don't forget about behavior analysis too. Besides AMSI, some sandbox won't detect your payload as malicious on online scans, but executing manually on the machine can trigger AV,specially macros.
 


Напишите ответ...
  • Вставить:
Прикрепить файлы
Верх