founder @apolytainc; i like butter croissants and security controls, uncontrollably eating both.
Oct 16, 2022 • 10 tweets • 3 min read
Some #lolbins [likely hw-related] call igc64.dll (Intel Graphics Shader Compiler for Intel(R) Graphics Accelerator), which then tries to LoadLibraryA on rasty_jitter64.dll (obviously from either CWD or %PATH%). Just export JitCreateCompilerData & run phoneactivate.exe toloadurdll
same with filehistory
Oct 16, 2022 • 11 tweets • 1 min read
Load your DLL payload with a MS-signed executable; deploymentcsphelper.exe, by setting %windir% to C:\dummy and planting your lib as dbghelp.dll under system32 of that dummy folder #lolbin#lolbas
Same with djoin.exe