Discord Server Twitter Donation Youtube Google+
Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
News Hackers Abusing Windows Management Interface Command Tool
#1
In The Name OF Allah
Al-Salam Alelkum

[Image: New-Project.jpg]

Quote:Attackers use to deliver a shortcut file (.lnk) through URL or link in email or as an attachment, once the user opens the file contains a WMIC command, it downloads the malicious file from the attacker’s remote server. The file downloaded from the remote server is the malicious XSL(eXtensible Stylesheet Language) file and the malicious XSL contains the javascript which is executed using another legitimate application mshta[.]exe used in running Microsoft HTML Application Host.
Researchers said the JavaScript contains a list of 52 domains and it chooses a random URL as well as the random port between 25010-25099 to download the HTA file.
https://gbhackers.com/hackers-abusing-wi...words/amp/


Wa Salam Alekum

[Image: 4Kxb0N1.gif]
We Are Anonymous, We Are Legion, We Do not Forgive, We do not Forget
Expect Us
Reply




Users browsing this thread: 2 Guest(s)