.. /AddinUtil.exe
Star

Execute

.NET Tool used for updating cache files for Microsoft Office Add-Ins.


Paths:

Resources:
Acknowledgements:

Detection:

Execute

  1. AddinUtil is executed from the directory where the 'Addins.Store' payload exists, AddinUtil will execute the 'Addins.Store' payload.

    C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddinUtil.exe -AddinRoot:.
    Use case
    Proxy execution of malicious serialized payload
    Privileges required
    User
    Operating systems
    Windows Vista, Windows 7, Windows 8, Windows 8.1, Windows 10, Windows 11
    ATT&CK® technique
    T1218