optiv / ScareCrow

ScareCrow - Payload creation framework designed around EDR bypass.
2.71k stars 503 forks source link

cmd.run() failed with exit status 1 #41

Closed tgelliott196 closed 2 years ago

tgelliott196 commented 2 years ago

failedtomakeexe.docx

when run makes random files onenote onedrive excel word, but never creates out file.

Tylous commented 2 years ago

Can you please provide the exact command you are running.

tgelliott196 commented 2 years ago

I've tried multiple variants of:

ScareCrow_3.01_windows_amd64.exe -I test.bin -domain www.microsoft.com or ScareCrow_3.01_windows_amd64.exe -I test.bin -domain www.microsoft.com -Loader dll -O blah.dll or ScareCrow_3.01_windows_amd64.exe -I test.bin -domain www.microsoft.com -Loader excel

Tylous commented 2 years ago

This is a windows issue playing not well with OSSSIGNCODE, I would recommend you try on Linux or OSX

tgelliott196 commented 2 years ago

Thank you. I'll put it on linux

On Thu, Feb 10, 2022 at 8:09 PM Tylous @.***> wrote:

This is a windows issue playing not well with OSSSIGNCODE, I would recommend you try on Linux or OSX

— Reply to this email directly, view it on GitHub https://github.com/optiv/ScareCrow/issues/41#issuecomment-1035695366, or unsubscribe https://github.com/notifications/unsubscribe-auth/ALSQ2YHAVSKXCYWGB5NR5TLU2ROTDANCNFSM5NSNGRWA . Triage notifications on the go with GitHub Mobile for iOS https://apps.apple.com/app/apple-store/id1477376905?ct=notification-email&mt=8&pt=524675 or Android https://play.google.com/store/apps/details?id=com.github.android&referrer=utm_campaign%3Dnotification-email%26utm_medium%3Demail%26utm_source%3Dgithub.

You are receiving this because you authored the thread.Message ID: @.***>