Avast WEBforum

Other => Viruses and worms => Topic started by: Skyler8 on March 25, 2019, 08:46:46 PM

Title: how did this happen?
Post by: Skyler8 on March 25, 2019, 08:46:46 PM
OK so i work on malware analyses in my free time when I'm doing something but for the last few days i been making a F.U.D. R.A.T. (Fully UnDetectable Remote Access Trojan) good so far however i have not distributed the R.A.T. but for the last few days i been getting a notification from the rat saying that JOHN has connected Who's john so i did a IP Geo-location search and traced it back to avast i still unaware how this happened. I'm using LIMERAT ]BTW it's open sourced found on GitHub (https://github.com/NYAN-x-CAT/Lime-RAT).
Picture below

Title: Re: how did this happen?
Post by: Skyler8 on March 25, 2019, 08:55:47 PM
picture should now be posted
Title: Re: how did this happen?
Post by: DavidR on March 25, 2019, 09:27:21 PM
It is preferable to attach images to the topic. 
And the post remains with your topic.

Some don't like going off site to unknown urls.
Title: Re: how did this happen?
Post by: Skyler8 on March 25, 2019, 09:37:52 PM
ok fixed it should be attached
Title: Re: how did this happen?
Post by: DavidR on March 26, 2019, 12:34:36 AM
Whilst not an Avast Team member.

I would suggest that it may well be being scanned by one of the avast shields.  Should that come across something new, not experienced by avast, so hash could well be being checked against avasts database.

Although not detected I just wonder if it could well be checked for analysis, though I don't know this for certain.