Code Monkey home page Code Monkey logo

not-anti-virus's Introduction

[Not Anti-Virus (Not AV)™]

An attmept to block malware before AV scans it.

Description

Not all things are seen as equal until you stare at it long enough!

With malware causing havoc across the globe, this browser extension is a PoC for blocking malware downloads using just the response headers. The research for Emotet can be found in this thread: https://twitter.com/ecstatic_nobel/status/1176267975537713152?s=19.

Demonstration blocking Mozi:

  • Connect to URLhaus
  • Open three (3) database entries for recent and active Mozi URLs that end with "Mozi.m"
  • Hightlight and open the URL in a new tab
  • Not AV detects it, file download is blocked, and the browser is redirected to 127.0.0.1

Demonstration blocking GuLoader:

  • Connect to URLhaus
  • Open three (3) database entries for recent and active GuLoader URLs that contain the word "encrypted"
  • Hightlight and open the URL in a new tab
  • Not AV detects it, file download is blocked, and the browser is redirected to 127.0.0.1

Demonstration blocking Emotet:

  • Connect to URLhaus
  • Open three (3) database entries for recent and active Emotet URLs
  • Hightlight and open the URL in a new tab
  • Not AV detects it, file download is blocked, and the browser is redirected to 127.0.0.1

NOTE: Out of the box, this will block the majority of:

  • GuLoader malware that contains the word "encrypted"
  • Emotet (or other file download) that has a cookie name built with the PHP uniqid function (or something similar) in the Set-Cookie header

This PoC can be strengthened by adding other indicators found in the response (or request) headers to avoid false-positives.

Not Anti-Virus

Support: notav [at] protonmail

not-anti-virus's People

Contributors

ecstatic-nobel avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar

Forkers

simrit1 croat79

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.