Windows cmd / LOLbins

Author Unprotect
Platform Windows
Language cmd
Technique LOLbins

Description:

The pcalua.exe utilities is used to execute a malicious PowerShell script (.ps1) .

Code

C:\> pcalua.exe -run "C:\malicious-script.ps1"

Created

December 13, 2022

Last Revised

April 22, 2024