Expand is a Windows utility used to expand one or more compressed CAB files.[1] It has been used by BBSRAT to decompress a CAB file into executable content.[2]

ID: S0361
Type: TOOL
Contributors: Matthew Demaske, Adaptforward

Platforms: Windows

Version: 1.0

Techniques Used

EnterpriseT1140Deobfuscate/Decode Files or InformationExpand can be used to decompress a local or remote CAB file into an executable.[1]
EnterpriseT1096NTFS File AttributesExpand can be used to download or copy a file into an alternate data stream.[3]
EnterpriseT1105Remote File CopyExpand can be used to download or upload a file over a network share.[3]