LUA from what I see (I do not use it at all so I haven’t researched) can be statically linked so you can create a fully portable executable with the LUA script in it.
Various obfuscations for the string can be used, from XOR, to replacing numbers with results of vectorised math.
We can go really creative here.
But again, it is an executable.
Not sure how different solutions will react to that, the ones that are aggressive towards low-trust executables (McAfee, Defender, Norton, Kaspersky and so on), and the ones that use aggressive static analysis and disassembling (Check Point, Deep Instinct), plus the ones that use emulation (CrowdStrike, Check Point, Palo Alto) won’t miss that.
Problem will be if additional tactics are applied as well (bloating and so on), but these will make distribution more difficult.
Some of the solutions above upload the full archives users download or save through email.
Various obfuscations for the string can be used, from XOR, to replacing numbers with results of vectorised math.
We can go really creative here.
But again, it is an executable.
Not sure how different solutions will react to that, the ones that are aggressive towards low-trust executables (McAfee, Defender, Norton, Kaspersky and so on), and the ones that use aggressive static analysis and disassembling (Check Point, Deep Instinct), plus the ones that use emulation (CrowdStrike, Check Point, Palo Alto) won’t miss that.
Problem will be if additional tactics are applied as well (bloating and so on), but these will make distribution more difficult.
Some of the solutions above upload the full archives users download or save through email.
Last edited:

