logo

Malicious Outlook Rule without an EXE

ID: 6da23064-435a-5180-8bf8-350d3813d975

STIX ID: report--6da23064-435a-5180-8bf8-350d3813d975

Feed Name: Black Hills Infosec Blog

Threat Score
70/100

Date Published: 2016-12-20

Date Updated: 2026-04-27

Author: BHIS

...
...

This write-up demonstrates an email-based technique to achieve remote code execution and C2 by leveraging Outlook rules to download and execute a VBE file that runs an encoded PowerShell Meterpreter reverse shell. The author details bypassing EXE download restrictions, AV detection of an autogenerated VBS payload, and a manually crafted VBScript that successfully launches a hidden PowerShell session to connect to an attacker-controlled server.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.