This commit is contained in:
Wietze
2021-01-10 15:04:52 +00:00
parent de50a47957
commit 14dca38278
147 changed files with 407 additions and 407 deletions

View File

@@ -2,7 +2,7 @@
Name: DefaultPack.EXE
Description: This binary can be downloaded along side multiple software downloads on the microsoft website. It gets downloaded when the user forgets to uncheck the option to set Bing as the default search provider.
Author: '@checkymander'
Created: '2020-10-01'
Created: 2020-10-01
Commands:
- Command: DefaultPack.EXE /C:"process.exe args"
Description: Use DefaultPack.EXE to execute arbitrary binaries, with added argument support.
@@ -14,9 +14,9 @@ Commands:
OperatingSystem: Windows
Full_Path:
- Path: C:\Program Files (x86)\Microsoft\DefaultPack\
Code_Sample:
Code_Sample:
- Code:
Detection:
Detection:
- IOC: DefaultPack.EXE spawned an unknown process
Resources:
- Link: https://twitter.com/checkymander/status/1311509470275604480.