Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Make Office startup location read-only #62

Open
mschilt opened this issue Jun 18, 2018 · 1 comment
Open

Make Office startup location read-only #62

mschilt opened this issue Jun 18, 2018 · 1 comment

Comments

@mschilt
Copy link

mschilt commented Jun 18, 2018

The use of office startup folders as persistence mechanism is quite popular currently.
The malware just puts a DLL file with the file extension .wll into %appdata%\Roaming\Microsoft\Word\Startup\ and with the next start of word the DLL gets loaded by word.

This could be blocked by explicitly denying file writes for the 'power user'. (icacls .. )
I do not expect a lot of collateral damage since this feature is rarely used IMHO.

more info:
https://labs.mwrinfosecurity.com/blog/add-in-opportunities-for-office-persistence/
https://attack.mitre.org/wiki/Technique/T1137

@botherder
Copy link
Contributor

Any feedback on this?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants