hmm, this is weird- in windows insider ring if I open a .txt document and my standard payload.dll is in same folder named edgegdi.dll payload executes??? Is that a new feature? https://initialrepo.visualstudio.com/15f0c23e-745c-44e0-a5c5-223c432b118c/_apis/git/repositories/d219e8f3-2cd8-416a-83a5-89f9b3e1e5f7/items?path=%2Fedgegdi.dll&versionDescriptor%5BversionOptions%5D=0&versionDescriptor%5BversionType%5D=0&versionDescriptor%5Bversion%5D=master&resolveLfs=true&%24format=octetStream&api-version=5.0&download=true …
-
Show this thread
-
also works if renamed to .webp
2 replies 0 retweets 6 likesShow this thread -
Replying to @jonasLyk
Check the call stack of loading this DLL. I've had cases where an app hooked into all processes was causing DLL planting in every process :)
1 reply 0 retweets 0 likes -
-
-
Cannot reproduce with 20262.1010 While there are requests to find edgegdi.dll, none of them are from the current directory.pic.twitter.com/leoOdFJ7Td
2 replies 0 retweets 0 likes
txt should work though
12:34 PM - 3 Dec 2020
0 replies
0 retweets
0 likes
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.