Freddy Ouzan Profile picture
founder @apolytainc; i like butter croissants and security controls, uncontrollably eating both.
Oct 16, 2022 10 tweets 3 min read
Some #lolbins [likely hw-related] call igc64.dll (Intel Graphics Shader Compiler for Intel(R) Graphics Accelerator), which then tries to LoadLibraryA on rasty_jitter64.dll (obviously from either CWD or %PATH%). Just export JitCreateCompilerData & run phoneactivate.exe toloadurdll same with filehistory
Oct 16, 2022 11 tweets 1 min read
Load your DLL payload with a MS-signed executable; deploymentcsphelper.exe, by setting %windir% to C:\dummy and planting your lib as dbghelp.dll under system32 of that dummy folder #lolbin #lolbas Same with djoin.exe