Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

mofcomp.exe #137

Open
rivitna opened this issue May 21, 2021 · 0 comments · May be fixed by #236
Open

mofcomp.exe #137

rivitna opened this issue May 21, 2021 · 0 comments · May be fixed by #236

Comments

@rivitna
Copy link

rivitna commented May 21, 2021

Please add mofcomp.exe (Compile, Execution)
Event Triggered Execution: Windows Management Instrumentation Event Subscription (T1546.003)
mofcomp.exe can be used to establish WMI Event Subscription persistence mechanisms configured from a .mof/.bmof file.

Example:
iisstt.dat
This BMOF-file contains malicious VBS-script

mofcomp.exe iisstt.dat
As a result, this script is injected in WMI repository and runs every day 23:00

danielgottt added a commit to danielgottt/LOLBAS that referenced this issue Jul 19, 2022
Create lolbas yml entry for the Windows binary "mofcomp.exe". This relates to issue LOLBAS-Project#137
@danielgottt danielgottt linked a pull request Jul 19, 2022 that will close this issue
@wietze wietze linked a pull request Oct 4, 2022 that will close this issue
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants