Meta tags:
description= Ieframe.dll is a living-of-the-land file containing unexpected functionality that can be abused by attackers; this page lists all its use cases.;
Headings (most frequently used words):
ieframe, dll, star, execute, paths, resources, acknowledgements, detections,
Text of the page (most frequently used words):
url (6), windows (5), ieframe (5), dll (5), https (4), com (4), #execute (3), file (3), bohops (3), executable (2), payload (2), calling (2), openurl (2), via (2), proxy (2), sigma (2), hexacorn (2), html (2), 2018 (2), and (2), for (2), tags, t1218, 011, att, technique, operating, systems, user, privileges, required, load, with, without, quotes, the, extension, can, renamed, use, case, rundll32, exe, path_absolute, launch, through, information, github, sigmahq, blob, 62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e, rules, process_creation, proc_creation_win_rundll32_susp_activity, yml, detections, adam, jimmy, acknowledgements, windows10dll, nirsoft, net, ieframe_dll, twitter, status, 997690405092290561, abusing, exported, functions, exposed, dcom, interfaces, pass, thru, command, execution, lateral, movement, http, www, blog, running, programs, jumping, edr, bypass, trampoline, part, resources, syswow64, system32, paths, internet, browser, translating, code, star, lolbas,
Text of the page (random words):
ieframe lolbas ieframe dll star execute url internet browser dll for translating html code paths c windows system32 ieframe dll c windows syswow64 ieframe dll resources http www hexacorn com blog 2018 03 15 running programs via proxy jumping on a edr bypass trampoline part 5 https bohops com 2018 03 17 abusing exported functions and exposed dcom interfaces for pass thru command execution and lateral movement https twitter com bohops status 997690405092290561 https windows10dll nirsoft net ieframe_dll html acknowledgements jimmy bohops adam hexacorn detections sigma https github com sigmahq sigma blob 62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e rules windows process_creation proc_creation_win_rundll32_susp_activity yml execute launch an executable payload via proxy through a n url information file by calling openurl rundll32 exe ieframe dll openurl path_absolute url use case load an executable payload by calling a url file with or without quotes the url file extension can be renamed privileges required user operating systems windows 10 windows 11 att ck technique t1218 011 tags execute url
|