From RunDLL32 to JavaScript then PowerShell, (Tue, May 18th)

This article has been indexed from SANS Internet Storm Center, InfoCON: green

I spotted an interesting script on VT a few days ago and it deserves a quick diary because it uses a nice way to execute JavaScript on the targeted system. The technique used in this case is based on very common LOLbin: RunDLL32.exe. The goal of the tool is, as the name says, to load a DLL and execute one of its exported function:

Read the original article: From RunDLL32 to JavaScript then PowerShell, (Tue, May 18th)