Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[BUG] FComm implants do not update "last seen" time in implant handler #229

Open
Console opened this issue Feb 9, 2021 · 0 comments
Open
Assignees
Labels
bug Something isn't working

Comments

@Console
Copy link
Contributor

Console commented Feb 9, 2021

Description

A clear and concise description of what the bug is.

Execution Environment:

All of this must be filled in

Data Value
Full Posh version (all the text between the === at the top of the Implant Handler) PoshC2 v7.3.0 (2c06985 2021-01-12 17:00:37)
Using Docker/containerisation? WSLv2

Implant Info

  • What implant does the problem occur on? FComm
  • How was the implant created? Created using scarecrow with donut shellcode x64

Defensive Technologies

  • Is the target environment running any particular defensive products? Defender, Carbon Black Cloud.

To Reproduce

Steps to reproduce the behavior:
Create new fcomm implant
run commands over a period of time on fcomm implant.

Expected behavior

last seen time within implant handler updates to show the time that fcomm last successfully communicated. - This does not occur, last seen time remains stuck at "initialisation" time.

Screenshots

image

Attach files if required

Additional context

I think this could be related to some of the side improvements to the implant handler brought in as part of the FComm branch.

@Console Console added the bug Something isn't working label Feb 9, 2021
@Console Console changed the title [BUG] [BUG] FComm implants do not update "last seen" time in implant handler Feb 9, 2021
@Console Console self-assigned this Feb 9, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

No branches or pull requests

1 participant