write.exe

Windows Write

Paths

  • C:\Windows\write.exe
  • C:\Windows\System32\write.exe
  • C:\Windows\SysWOW64\write.exe

Commands

Execute

Executes a binary provided in default value of `HKCU\Software\Microsoft\Windows\CurrentVersion\App Paths\wordpad.exe`.

Use case: Execute binary through legitimate proxy. This might be utilized to confuse detection solutions that rely on parent-child relationships.

Privileges: User

write.exe

Detection

Resources