2018-04-18 16:35:07 +00:00
|
|
|
## InfDefaultInstall.exe
|
|
|
|
|
|
|
|
* Functions: Execute
|
|
|
|
|
|
|
|
```
|
|
|
|
InfDefaultInstall.exe Infdefaultinstall.inf
|
|
|
|
```
|
|
|
|
|
|
|
|
Acknowledgements:
|
|
|
|
* Kyle Hanslovan - @kylehanslovan
|
|
|
|
|
|
|
|
Code sample:
|
2018-04-24 07:53:32 +00:00
|
|
|
* [Infdefaultinstall.inf](https://raw.githubusercontent.com/api0cradle/LOLBAS/master/OSBinaries/Payloads/Infdefaultinstall.inf)
|
|
|
|
* [Infdefaultinstall_calc.sct](https://raw.githubusercontent.com/api0cradle/LOLBAS/master/OSBinaries/Payloads/Infdefaultinstall_calc.sct)
|
2018-04-18 16:35:07 +00:00
|
|
|
|
|
|
|
Resources:
|
|
|
|
* https://twitter.com/KyleHanslovan/status/911997635455852544
|
|
|
|
* https://gist.github.com/KyleHanslovan/5e0f00d331984c1fb5be32c40f3b265a
|
|
|
|
* https://blog.conscioushacker.io/index.php/2017/10/25/evading-microsofts-autoruns/
|
|
|
|
|
|
|
|
Full path:
|
|
|
|
```
|
|
|
|
c:\windows\system32\Infdefaultinstall.exe
|
|
|
|
c:\windows\sysWOW64\Infdefaultinstall.exe
|
|
|
|
```
|
|
|
|
|
|
|
|
Notes:
|
|
|
|
Some specific details about the binary file.
|
|
|
|
|
|
|
|
|
|
|
|
|