Mofcomp.exe

type: OSBinaries
Compiler that parses a file containing MOF statements and adds the classes and class instances defined in the file to the WMI repository. Threat actors can leverage this binary to install malicious MOF scripts

Full path

C:\Windows\System32\wbem\mofcomp.exe
C:\Windows\SysWOW64\wbem\mofcomp.exe

Commands

  1. ExecuteUser T1047

    Threat actors can use mofcomp.exe to register a malicious MOF file as a new class in the WMI repository

    mofcomp.exe {PATH_ABSOLUTE:.mof}

    Abuse of mofcomp.exe to parse a file which contains MOF statements in order create new classes as part of the WMI repository

    os: Windows Vista, Windows 7, Windows 8, Windows 8.1, Windows 10, Windows 11, Windows Server 2008+

    Execute: MOF

Detection

Resources

acknowledgement: Daniel Gott @gott_cyber, The DFIR Report @TheDFIRReport, Nasreddine Bencherchali @nas_bench