Interesting way to embed payload to .REGs

Discussion in 'Scripting' started by acer-5100, Jul 31, 2022.

  1. acer-5100

    acer-5100 MDL Guru

    Dec 8, 2018
    3,781
    2,698
    120
    https://www.x86matthew.com/view_post?id=embed_exe_reg

    Well, that's looks like something that in the linux/unix world is used since the dawn of time, but it's the first time i see it on Windows.

    Think, for example, to VMware's installer that doesn't rely on native .deb/ .rpm/ .whatever installer infrastructure, but is practically a shell script chained with the binary payload in a single big file.

    I'm terrified to think what this method can do when in the hands of people like @abbodi1406 :p
     
  2. abbodi1406

    abbodi1406 MDL KB0000001

    Feb 19, 2011
    16,226
    84,917
    340
  3. acer-5100

    acer-5100 MDL Guru

    Dec 8, 2018
    3,781
    2,698
    120

    I haven't really played yet with that method, just crossed that article and I though was worth to share it.

    I see, thanks.

    Maybe one of the two guys took inspiration from other's work, or maybe they ended to the same method independently, as often happens.;)