Giter Club home page Giter Club logo

foureye's Introduction

FourEye(重明) - AV Evasion Tool For Red Team Ops

用于快速生成免杀的 EXE 可执行文件,目前拥有三种免杀方法。

 ______                   ___           
(_) |                    / (_)          
   _|_  __          ,_   \__         _  
  / | |/  \_|   |  /  |  /    |   | |/  
 (_/   \__/  \_/|_/   |_/\___/ \_/|/|__/
                                 /|     
                                 \|   


                    v1.8 stable !
                    author lengyi@HongHuSec Lab !

 FourEye BypassFrameWork | BypassAV your shellcode && exe 

声明

#f03c15 仅限用于技术研究和获得正式授权的测试活动。

安装方法

推荐使用kali linux系统安装.

git clone https://github.com/lengjibo/FourEye.git

cd FourEye

chmod 755 setup.sh

./setup.sh

python3 BypassFramework.py

因为是linux下编译,所以编译文件会有体积大的问题,该工具为三天内的产物,可能有不少bug,欢迎在issus处与我反馈

使用方法

shellcode

python3 BypassFramework.py

image

选择shellcode

image

选择免杀方式,1:Fiber、2:APC、3:图片分离,选择加密方式,xor或者rot13,然后输入shellcode,选择位数,x64或者x86

image

执行execute

image

exe

选择exe,然后输入exe即可

image

demo。已上传至B站。

https://www.bilibili.com/video/BV1zy4y1S7ZM/

https://www.bilibili.com/video/BV1Sh411Z7qc

https://www.bilibili.com/video/BV1b54y1x7RT

引用

大多数方法均为网上已经公开的方法,本人只是对其整合、优化,多来自于ired,感谢其分享精神。

update

2020.2.03: 火绒已对其标记,且用且珍惜

2020.12.14:增加其对exe的免杀,方法参考@bats3c,若使用报错请安装x86_64-w64-mingw32-gcc

2021.01.03: 增加x86、x64的支持

2021.01.09: 隐藏窗口

2021.01.26: 增加UUID免杀方法,修复部分bug,增加安装脚本@zhzyker

TODO

  • 增加更多的免杀、shellcode加密方法

foureye's People

Contributors

lengjibo avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

foureye's Issues

弹窗

可以尝试去掉弹窗和桌面程序

cat: /etc/redhat-release: No such file or directory

It's show follow this:

[+] 测试网络可用
[+] Python依赖存在
[*] 开始检查Linux系统依赖程序
cat: /etc/redhat-release: No such file or directory
[-] 脚本不适用于该系统

Im using ubuntu 20.04
pls let me know what happend ?

Dll Output Better

Hi thanks for this great tool , please can you make the generated output .dll not .exe i think is better for evasion

sh: 1: i686-w64-mingw32-g++: not found

python3 pip环境均已配置,运行系统kali,已root账户运行,运行软件后报错:
sh: 1: i686-w64-mingw32-g++: not found
如何解决?

您好,请教一个问题

请问一下,我用您得软件免杀一款31mb得exe软件,但是经过一个下午
,CPU是一直保持在为这个免杀软件运作,但是一直卡在
[i] Begining encryption via XOR,请问知道为什么吗?

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.