coregen.exe

type: OtherMSBinaries
Binary coregen.exe (Microsoft CoreCLR Native Image Generator) loads exported function GetCLRRuntimeHost from coreclr.dll or from .DLL in arbitrary path. Coregen is located within “C:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0" or another version of Silverlight. Coregen is signed by Microsoft and bundled with Microsoft Silverlight.

Full path

C:\Program Files\Microsoft Silverlight\5.1.50918.0\coregen.exe
C:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\coregen.exe

Commands

  1. ExecuteUser T1055

    Execute DLL code

    coregen.exe /L {PATH_ABSOLUTE:.dll} dummy_assembly_name

    Loads the target .DLL in arbitrary path specified with /L.

    os: Windows

    Execute: DLL

  2. ExecuteUser T1055

    Execute DLL code

    coregen.exe dummy_assembly_name

    Loads the coreclr.dll in the corgen.exe directory (e.g. C:\Program Files\Microsoft Silverlight\5.1.50918.0).

    os: Windows

    Execute: DLL

  3. AWL BypassUser T1218

    Execute DLL code

    coregen.exe /L {PATH_ABSOLUTE:.dll} dummy_assembly_name

    Loads the target .DLL in arbitrary path specified with /L. Since binary is signed it can also be used to bypass application whitelisting solutions.

    os: Windows

    Execute: DLL

Detection

Resources

acknowledgement: Nicky Tyrer, Evan Pena, Casey Erikson