Abusing Trusted Applications with Nested Execution
ID: adf527d8-9fad-54fd-9aac-919061db368b
STIX ID: report--adf527d8-9fad-54fd-9aac-919061db368b
Feed Name: Huntress Blog
Threat Score
Huntress investigators found multiple Windows services invoking the same executable (WseClientSvc.exe). By reversing the binary they discovered it attempts to load a .NET assembly passed as an argument; building a simple passthrough .NET module allowed them to use the signed Microsoft binary to execute arbitrary code (demonstrated with calc.exe), illustrating a living-off-the-land code execution technique.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
