S
S
Sazoks2019-07-05 22:59:47
Burglary protection
Sazoks, 2019-07-05 22:59:47

Question about meterpeter (exe vs dll)?

Here is how it was.
I generated the meterpeter stuffing with aes256 and rc4.
Further, from one project on the git, I downloaded one file, where I replaced the shell with my own.
In general, the whole point boils down to the fact that you simply compile everything into a dll and that's it - here's an encrypted meterpeter for you. I compiled an exe and a dll next to it. Noooo! When I got a session with exe, the defender fired almost any of my actions and the session ended! And when I got the session through the dll (launched using rundll32.exe), then I could do whatever my heart desires! The scan didn't work either.
I don't understand why this is happening. What's the matter? Why does exe burn so much at the slightest gesture, and dll - not at all ???

Answer the question

In order to leave comments, you need to log in

1 answer(s)
A
Alexander +, 2019-07-28
@AlexanderMi

Because the subject is not intended for self-execution. It's always a DLL that someone somewhere intentionally/accidentally loads and you're good to go.

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question