Using DLL hijacking (source)

  1. User has SMB access to another host
  2. Upload EXE + DLL to target host
  3. Use wmiexec.py to execute EXE
  4. Receive beacon via the DLL execution