CFF Explorer.exe
. Once the program is executed, it attempts to load CFF ExplorerENU.dll
from the location the program is installed to, however that DLL cannot be loaded (note the NAME NOT FOUND) as it does not exist in the given path:evil-meterpreter64.dll
to C:\Program Files\NTCore\Explorer Suite
and rename it to CFF ExplorerENU.dll
4856
which then kicked off a rundll32 (1872
) which then established a connection to 10.0.0.5: