January 2019
Intermediate to advanced
548 pages
12h 7m
English
The attack method involves Disk Cleanup, the Windows utility designed to free up space on the hard drive. Default scheduled tasks on Windows 10 revealed a task named SilentCleanup, which executes the Disk Cleanup process cleanmgr.exe with the highest privileges, even if executed by an unprivileged user. The process creates a new folder named GUID in the Temp directory and copies an executable and various DLLs into it.
The executable is then launched and it starts loading the DLLs in a certain order, as shown in the following screenshot:

Read now
Unlock full access