.. / DefaultPack.EXE
Star

This binary can be downloaded along side multiple software downloads on the microsoft website. It gets downloaded when the user forgets to uncheck the option to set Bing as the default search provider.


Paths:


Resources:
https://twitter.com/checkymander/status/1311509470275604480.

Acknowledgement:
checkymander - @checkymander


Detection:
DefaultPack.EXE spawned an unknown process



Execute

Use DefaultPack.EXE to execute arbitrary binaries, with added argument support.
DefaultPack.EXE /C:"process.exe args"
Usecase:Can be used to execute stagers, binaries, and other malicious commands.
Privileges required:User
OS:Windows
Mitre:T1218