.. /Change.exe
Star

Execute (EXE, Rename)

Remote Desktop Services MultiUser Change Utility

Paths:

Acknowledgements:

Detections:

Execute

  1. Once executed, change.exe will execute chgusr.exe in the same folder. Thus, if change.exe is copied to a folder and an arbitrary executable is renamed to chgusr.exe, change.exe will spawn it. Instead of user, it is also possible to use port or logon as command-line option.

    change.exe user
    Use case

    Execute an arbitrary executable via trusted system executable.

    Privileges required
    User
    Operating systems
    Windows 10, Windows 11
    ATT&CK® technique
    T1218
    Tags
    Execute: EXE
    Requires: Rename