Skip to content
This repository has been archived by the owner. It is now read-only.

Will not work on windows 10 #1232

Closed
drforbin opened this issue Sep 16, 2018 · 6 comments
Closed

Will not work on windows 10 #1232

drforbin opened this issue Sep 16, 2018 · 6 comments

Comments

@drforbin
Copy link

@drforbin drforbin commented Sep 16, 2018

Empire Version

latest

OS Information (Linux flavor, Python version)

windows 10

Expected behavior and description of the error, including any actions taken immediately prior to the error. The more detail the better.

I cannot get the launcher to connect back to the listener.
When it's run on windows 10 the powershell launcher just exits
It works on windows 7

Screenshot of error, embedded text output, or Pastebin link to the error

Any additional information

@mr64bit
Copy link
Contributor

@mr64bit mr64bit commented Sep 16, 2018

@drforbin
Copy link
Author

@drforbin drforbin commented Sep 16, 2018

Interesting. Thank you. I have designed other powershell launchers which stage shellcode of my own design and it's not caught. Please explain to me why empire is being caught?

@mr64bit
Copy link
Contributor

@mr64bit mr64bit commented Sep 17, 2018

@xorrior xorrior closed this Sep 17, 2018
@poopaapoopaa
Copy link

@poopaapoopaa poopaapoopaa commented Sep 20, 2018

This trick was working until a few days ago. Now it's detected even when SafeChecks is false.

If the detection is overridden and the file is allowed to run, stage 1 stager is sent, and then blocked.
The process ends with:

[*] Sending POWERSHELL stager (stage 1) to ..

If real time virus protection is turned off completely, it works as before.

The -ver 2 option doesn't seem to work at all.

Any further ideas?

@drforbin
Copy link
Author

@drforbin drforbin commented Sep 20, 2018

Yes, I am having the same problem.
My costume made shellcode works fine.

@ghost
Copy link

@ghost ghost commented Apr 20, 2019

Could you please share your method for generating said shellcode?

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Linked pull requests

Successfully merging a pull request may close this issue.

None yet
4 participants