Skip to content

Monkey flagged on Windows Defender with signature Exploit:Python/MS08067.G!MSR and Trojan:Win32:Wacatac.D6!ml #801

@ShayNehmad

Description

@ShayNehmad

Describe the bug

seems like updated Defender doesn't like the new version 😞 See attached image.
It's probably a binary signature on the Python shellcode from here: https://github.com/guardicore/monkey/blob/develop/monkey/infection_monkey/exploit/win_ms08_067.py

To Reproduce

Steps to reproduce the behavior:

  • Run monkey with Windows defender enabled
  • As soon as monkey unpacks it's contents, ms08_067.py gets tagged as a threat.

Expected behavior

Monkey shouldn't trip AV. We need to employ basic evasion techniques so that our users experience seamless operation on Windows machines.

Screenshots

image

Machine version (please complete the following information):

  • OS: Windows

Metadata

Metadata

Assignees

Labels

BugAn error, flaw, misbehavior or failure in the Monkey or Monkey Island.

Type

No type

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions