Date: 26 July 2025
Started from the exploit: https://gist.github.com/gboddin/6374c04f84b58cef050f5f4ecf43d501/
Extracted the multiple layers to the final payload, the powershell script messing with the MachineKey.
Fred Raynal <fraynal-AT-quarkslab.com>