Run applications and scripts using Acer's RunCmd
ID: f9125f6f-0692-58ba-bdaf-44129f2f1108
STIX ID: report--f9125f6f-0692-58ba-bdaf-44129f2f1108
Feed Name: Blaze's Security Blog
This report highlights Acer’s signed RunCmd utility as a living-off-the-land binary that can execute commands or scripts silently (default behavior or via the /F flag), enabling stealthy execution without an obvious parent process. It provides MD5 hashes for both 64-bit and 32-bit versions, describes expected logging behavior (RunCmdLog folder and timestamped logs), and offers defensive insights for detection, making it relevant for both offensive and defensive operations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
