.. /AddinUtil.exe
Star

.NET Tool used for updating cache files for Microsoft Office Add-Ins.


Paths:

Resources:
Acknowledgements:

Detection:

Execute

AddinUtil is executed from the directory where the 'Addins.Store' payload exists, AddinUtil will execute the 'Addins.Store' payload.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddinUtil.exe -AddinRoot:.
Usecase: Proxy execution of malicious serliaized payload
Privileges required: User
OS: Windows Vista, Windows 7, Windows 8, Windows 8.1, Windows 10, Windows 11
MITRE ATT&CK®: T1218