Skip to content
This repository has been archived by the owner on Dec 11, 2018. It is now read-only.

Latest commit

 

History

History
38 lines (25 loc) · 1.03 KB

Advpack.md

File metadata and controls

38 lines (25 loc) · 1.03 KB

UPDATE BOOKMARKS - PROJECT MOVED TO A DEDICATED PROJECT SITE. THIS SITE WILL NOT BE UPDATED ANYMORE, BUT WILL BE KEPT FOR HISTORICAL REASONS.

New site: https://github.com/LOLBAS-Project/LOLBAS Web portal: https://lolbas-project.github.io/

Advpack.dll

  • Functions: Execute
rundll32.exe advpack.dll,LaunchINFSection c:\test.inf,DefaultInstall_SingleUser,1,     
rundll32.exe advpack.dll,RegisterOCX calc.exe

Acknowledgements:

  • Jimmy - @bohops

Code sample:

Resources:

Full path:

c:\windows\system32\advpack.dll
c:\windows\sysWOW64\advpack.dll

Notes:

Detection: