Weaponizing .SettingContent-ms Extensions for Code Execution
ID: 94f42555-9fa9-5d70-8ede-b2b239866413
STIX ID: report--94f42555-9fa9-5d70-8ede-b2b239866413
Feed Name: TrustedSec blog
This report documents the weaponization of .SettingContent-ms files to achieve remote code execution on Windows systems by abusing the DeepLink element to call trusted binaries (e.g., mshta.exe) that fetch and execute malicious HTA payloads. The author demonstrates PoCs using obfuscated PowerShell/meterpreter payloads, details a 517-character DeepLink limit, provides an automation script (auto_SettingContent-ms), reports successful red-team use, and recommends mitigations such as blocking the file type at the perimeter or changing file associations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
