I quickly developed a dll that kills calc.exe when started from anything else than explorer.exe.
This way, you can mess with all those PoCs that launch calc.exe 😉
nocalcpoc_V0_0_0_1.zip (https)
MD5: 05798543571B45E19536181DC7346330
SHA256: ED0FEDC6096420F6F09F4980A1CE36F7C4BC0A8C9191F4DFC27FA4C77D547976
Haha, what the hell! I pitty the poor researcher you bullied with this! haha, this is epic.
Comment by Anonymous — Sunday 16 August 2015 @ 2:48