Skip to content

PoC for generating bthprops.cpl module designed to be loaded by Fsquirt.exe LOLBin

Notifications You must be signed in to change notification settings

mhaskar/FsquirtCPLPoC

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

5 Commits
 
 
 
 
 
 
 
 

Repository files navigation

Fsquirt.exe Windows binary attempts to load a Control Panel applet (CPL) called bthprops.cpl from its current working directory. When bthprops.cpl is present alongside fsquirt.exe, the binary loads it and executes a MessageBox from DLLMain.

This PoC code generates a malicious bthprops.cpl file that can be loaded by fsquirt.exe. The included build.sh script compiles the CPL module for you.

Fsquirt.exe PoC screenshot

About

PoC for generating bthprops.cpl module designed to be loaded by Fsquirt.exe LOLBin

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published