Skip to content

Latest commit

 

History

History
42 lines (27 loc) · 1.06 KB

Xwizard.md

File metadata and controls

42 lines (27 loc) · 1.06 KB

UPDATE BOOKMARKS - PROJECT MOVED TO A DEDICATED PROJECT SITE. THIS SITE WILL NOT BE UPDATED ANYMORE, BUT WILL BE KEPT FOR HISTORICAL REASONS.

New site: https://github.com/LOLBAS-Project/LOLBAS Web portal: https://lolbas-project.github.io/

Xwizard.exe

  • Functions: DLL hijack, Execute
xwizard.exe     

xwizard RunWizard {00000001-0000-0000-0000-0000FEEDACDC}    

Acknowledgements:

  • Adam - @Hexacorn
  • Nick Tyrer - @nicktyrer

Code sample:

Resources:

Full path:

c:\windows\system32\xwizard.exe
c:\windows\sysWOW32\xwizard.exe

Notes: DLL hijack/Sideloading needs to copy out xwizard.exe to a user controlled folder. If you add your own version of xwizard.dll it will execute when you start xwizard.exe.

Xwizard RunWizard requires you to import registry keys that points to external SCT file.