Welcome to our

Cyber Security News Aggregator

.

Cyber Tzar

provide a

cyber security risk management

platform; including automated penetration tests and risk assesments culminating in a "cyber risk score" out of 1,000, just like a credit score.

[SANS ISC] From RunDLL32 to JavaScript then PowerShell

published on 2021-05-18 10:31:14 UTC by Xavier
Content:

I published the following diary on isc.sans.edu: “From RunDLL32 to JavaScript then PowerShell“:

I spotted an interesting script on VT a few days ago and it deserves a quick diary because it uses a nice way to execute JavaScript on the targeted system. The technique used in this case is based on very common LOLbin: RunDLL32.exe. The goal of the tool is, as the name says, to load a DLL and execute one of its exported function:

C:\> rundll32.exe sample.dll,InvokedFunction()

Many Windows OS functions can be invoked through RunDLL32… [Read more]

The post [SANS ISC] From RunDLL32 to JavaScript then PowerShell appeared first on /dev/random.

Article: [SANS ISC] From RunDLL32 to JavaScript then PowerShell - published over 3 years ago.

https://blog.rootshell.be/2021/05/18/sans-isc-from-rundll32-to-javascript-then-powershell/   
Published: 2021 05 18 10:31:14
Received: 2021 06 06 09:04:42
Feed: /dev/random
Source: /dev/random
Category: Cyber Security
Topic: Cyber Security
Views: 3

Custom HTML Block

Click to Open Code Editor