The list of LOLBAS files that can be used for malicious purposes will soon include the main executables for the Microsoft Outlook email client and the Access database management system
See also: Microsoft Office gets a new default font

The main executable for the Microsoft Publisher application has already been confirmed to be able to download payloads from a remote server.
LOLBAS stands for Living-off-the-land Binaries and Scripts and are usually described as signed files that are either native to the Windows or downloaded from Microsoft. They are legitimate tools that hackers can abuse to download and/or execute payloads without triggering defense mechanisms.
According to recent research, even executables that are not signed by Microsoft serve purposes that are useful in attacks, such as reconnaissance.
The LOLBAS project currently lists over 150 Windows-related binaries, libraries, and scripts that can help attackers execute or download malicious files or bypass whitelists.
Nir Chako, a security researcher at Pentera, a company that provides an automated security validation solution, recently began discovering new LOLBAS files by examining executables in the Microsoft Office suite.
See also: Cyberattack on Capita disrupted access to Microsoft Office 365 apps
He tested them all manually and found three – MsoHtmEd.exe, MSPub.exe, and ProtocolHandler.exe – that could be used as third-party file downloaders. Later in his research, Chako discovered that MsoHtmEd could also be used to execute files.

Motivated by this initial success and already knowing the algorithm to find the appropriate files manually, the researcher developed a script to automate the verification process and cover a larger pool of executable files more quickly.
In a blog post, he explains the improvements added to the script that allowed binaries to be registered on Windows and tested for download capabilities beyond their intended design. In total, the Pentera researcher discovered 11 new files with download and execution capabilities that meet the principles of the LOLBAS project.
MSPub.exe, Outlook.exe and MSAccess.exe stand out, which an attacker or penetration tester could use to download third-party files, the researcher says.
See also: Microsoft Office: How to use it for free
While MSPub has been confirmed to be capable of downloading arbitrary payloads from a remote server, the other two have not yet been added to the LOLBAS list. They were not included due to a technical error, Chako said.
LOLBAS files are often exploited by attackers to launch attacks that are difficult to detect by most security systems. This is because these files are, in essence, normal components of the Windows operating system used for legitimate functions. This is an important reason why security professionals should be familiar with LOLBAS files and the ways in which they can be exploited.
