Extrac32.exe

Extract to ADS, copy or overwrite a file with Extrac32.exe

Paths

  • C:\Windows\System32\extrac32.exe
  • C:\Windows\SysWOW64\extrac32.exe

Commands

ADS

Extracts the source CAB file into an Alternate Data Stream (ADS) of the target file.

Use case: Extract data from cab file and hide it in an alternate data stream.

Privileges: User

extrac32 {PATH_ABSOLUTE:.cab} {PATH_ABSOLUTE}:file.exe

ADS

Extracts the source CAB file on an unc path into an Alternate Data Stream (ADS) of the target file.

Use case: Extract data from cab file and hide it in an alternate data stream.

Privileges: User

extrac32 {PATH_ABSOLUTE:.cab} {PATH_ABSOLUTE}:file.exe

Download

Copy the source file to the destination file and overwrite it.

Use case: Download file from UNC/WEBDav

Privileges: User

extrac32 /Y /C {PATH_SMB} {PATH_ABSOLUTE}

Copy

Command for copying file from one folder to another

Use case: Copy file

Privileges: User

extrac32.exe /C {PATH_ABSOLUTE:.source.exe} {PATH_ABSOLUTE:.dest.exe}

Detection

Resources