This is a Cobalt Strike (CS) Beacon Object File (BOF) which exploits the CMSTPLUA COM interface. It masquerade the PEB of the current process to a Windows process, and then utilises COM Elevation ...
Let’s say you try to start an application by using elevated permissions. For example, you right-click cmd.exe and select Run as administrator. A User Account ...