mttaggart / wtfbins

WTF are these binaries doing?! A list of benign applications that mimic malicious behavior.
MIT License
142 stars 10 forks source link

[New WTFBin]: code.exe spawn cmd.exe #48

Closed ThureinOo closed 6 months ago

ThureinOo commented 10 months ago
mttaggart commented 6 months ago

Hey @ThureinOo, thank you so much for your submission, and your patience!

Although cmd.exe by itself can be strange, I do not think it is unexpected for a code editor to be kicking off command prompts, especially given the nature of many plugins.

This submission also doesn't show that the command line params are, so there's not a lot to go on. Regardless, given the nature of VS Code, I don't know if I'm ready to call this a WTFBin. If you provide the command line and it looks particularly sus, like base64-encoded commands, we can revisit this.