12.9K subscribers
550 photos
27 videos
24 files
890 links
This channel discusses:

— Offensive Security
— RedTeam
— Malware Research
— OSINT
— etc

Disclaimer:
t.me/APT_Notes/6

Chat Link:
t.me/APT_Notes_PublicChat
Download Telegram
This media is not supported in your browser
VIEW IN TELEGRAM
LOLBAS WorkFolders.exe

"C:\Windows\System32\WorkFolders.exe" (signed by MS) can be used to run arbitrary executables in the current working directory with the name control.exe. It's like a new rundll32.exe lolbin but for EXEs!

#lolbin #lolbas
This media is not supported in your browser
VIEW IN TELEGRAM
LOLBAS Cmdl32.exe

It's like a new certutil.exe but absolutely unheard of by any antivirus software!
"C:\Windows\System32\Cmdl32.exe" (signed by MS) is for you.

#lolbin #lolbas
LOLBIN — wlrmdr

Action on click:
wlrmdr.exe -s 60000 -f 1 -t "Important" -m "Click this dude!" -a 10 -u cmd

You can use "-a 11" to skip the click requirement and spawn your process immediately:
wlrmdr -s 0 -f 0 -t 0 -m 0 -a 11 -u cmd

#windows #wlrmdr #lolbin #lolbas