.. /Zipfldr.dll
Star

Execute

Compressed Folder library


Paths:

Resources:
Acknowledgements:

Detection:

Execute

  1. Launch an executable payload by calling RouteTheCall.

    rundll32.exe zipfldr.dll,RouteTheCall calc.exe
    Use case
    Launch an executable.
    Privileges required
    User
    Operating systems
    Windows 10, Windows 11
    ATT&CK® technique
    T1218.011
  2. Launch an executable payload by calling RouteTheCall (obfuscated).

    rundll32.exe zipfldr.dll,RouteTheCall file://^C^:^/^W^i^n^d^o^w^s^/^s^y^s^t^e^m^3^2^/^c^a^l^c^.^e^x^e
    Use case
    Launch an executable.
    Privileges required
    User
    Operating systems
    Windows 10, Windows 11
    ATT&CK® technique
    T1218.011