Scriptrunner.exe

Execute binary through proxy binary to evade defensive counter measures

Paths

  • C:\Windows\System32\scriptrunner.exe
  • C:\Windows\SysWOW64\scriptrunner.exe

Commands

Execute

Executes executable

Use case: Execute binary through proxy binary to evade defensive counter measures

Privileges: User

Scriptrunner.exe -appvscript {PATH:.exe}

Execute

Executes cmd file from remote server

Use case: Execute binary through proxy binary from external server to evade defensive counter measures

Privileges: User

ScriptRunner.exe -appvscript {PATH_SMB:.cmd}

Detection

Resources