logo


Finger.exe & ClickFix, (Sun, Nov 16th)

ID: bd37e252-2abb-5ca0-89ee-9db262757c5a

STIX ID: report--bd37e252-2abb-5ca0-89ee-9db262757c5a

Feed Name: SANS ISC Diary

Date Published: 2025-11-16

Date Updated: 2026-04-19

...
...

This note describes the use of Windows finger.exe as a LOLBin in ClickFix attacks to fetch malicious scripts over the finger protocol. It emphasizes that finger uses TCP port 79 (unchangeable) and is not proxy-aware, outlining how explicit versus transparent proxy configurations impact its ability to communicate in corporate networks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.