[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fCAc8YI7dsQU9li3_mirVylj5nAhQVHCnI2V4p8H9d0k":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":52,"createdAt":52,"_status":51},469,"What detection and defense measures are recommended against the MSDTC backdoor?","Detection involves checking if a suspicious `oci.dll` exists in `%windir%\\system32\\`, as this DLL is not native to Windows. For defense, it is recommended to disable the MSDTC service on regular user hosts, as it is often unnecessary for typical workstations. Additionally, monitoring process creation and DLL loads by `msdtc.exe` can help identify malicious activity.","\u003Cp>Detection involves checking if a suspicious `oci.dll` exists in `%windir%\\system32\\`, as this DLL is not native to Windows. For defense, it is recommended to disable the MSDTC service on regular user hosts, as it is often unnecessary for typical workstations. Additionally, monitoring process creation and DLL loads by `msdtc.exe` can help identify malicious activity.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fuse-msdtc-to-maintain-persistence\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-detection-and-defense-measures-are-recommended-against-the-msdtc-backdoor-1777483503319","detection, defense, disable MSDTC, oci.dll monitoring, security",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":48,"updatedAt":49,"createdAt":50,"_status":51},117,"Use msdtc to maintain persistence","use-msdtc-to-maintain-persistence","Learn how MSDTC service DLL hijacking enables persistence, bypasses Autoruns, and methods for detection and defense in Windows environments.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Cp>---\u003C\u002Fp>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>A backdoor previously used by Shadow Force in a domain environment, leveraging the MSDTC service to load a DLL for achieving persistence and bypassing Autoruns' detection of startup items. This article will test it, introduce more exploitation techniques, and analyze defense methods.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Introduction to MSDTC\u003C\u002Fli>\u003Cli>Backdoor Concept\u003C\u002Fli>\u003Cli>Backdoor Verification\u003C\u002Fli>\u003Cli>More Testing and Exploitation Methods\u003C\u002Fli>\u003Cli>Detection and Defense\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Introduction to MSDTC\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>MSDTC:\u003C\u002Fh3>\u003Cul>\u003Cli>Corresponding service MSDTC, full name Distributed Transaction Coordinator, this service is started by default in Windows systems\u003C\u002Fli>\u003Cli>Corresponding process msdtc.exe, located at %windir%\\system32\\\u003C\u002Fli>\u003Cli>msdtc.exe is the Microsoft Distributed Transaction Coordinator, this process invokes the system's Microsoft Personal Web Server and Microsoft SQL Server\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x03 Backdoor Concept\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>\u003Cstrong>Reference link:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>http:\u002F\u002Fblog.trendmicro.com\u002Ftrendlabs-security-intelligence\u002Fshadow-force-uses-dll-hijacking-targets-south-korean-company\u002F\u003C\u002Fp>\u003Cp>The concept introduced in the article is as follows:\u003C\u002Fp>\u003Cp>When a computer joins a domain and the MSDTC service starts, it searches the registry HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\MSDTC\\MTxOCI\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017971471_0_366ce87e92.jpeg\">\u003C\u002Fp>\u003Cp>It loads three DLLs respectively: oci.dll, SQLLib80.dll, xa80.dll\u003C\u002Fp>\u003Cp>However, notably,\u003Cstrong>Windows systems do not include oci.dll by default\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>That is to say, rename payload.dll to oci.dll and save it under %windir%\\system32\\\u003C\u002Fp>\u003Cp>When the MSDTC service starts on computers in the domain, it will load this dll to achieve code execution\u003C\u002Fp>\u003Ch2>0x04 Backdoor Verification\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Test System: Win7 x64\u003C\u002Fp>\u003Cp>Set up the domain environment, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017982877_1_6f1aec569e.jpeg\">\u003C\u002Fp>\u003Cp>Use Procmon to monitor the startup process of msdtc, filter the process msdtc.exe, and view file operations, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017987633_2_ae678245f6.jpeg\">\u003C\u002Fp>\u003Cp>msdtc.exe does indeed attempt to load oci.dll, and since oci.dll does not exist by default in the system, the loading fails\u003C\u002Fp>\u003Cp>Use a 64-bit test dll, download link as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Save it under %windir%\\system32\\\u003C\u002Fp>\u003Cp>Terminate the process msdtc.exe, command line parameters as follows:\u003C\u002Fp>\u003Cp>taskkill \u002Ff \u002Fim msdtc.exe\u003C\u002Fp>\u003Cp>Waiting for msdtc.exe to restart\u003C\u002Fp>\u003Cp>After waiting for a while, mstdc.exe restarts and successfully loads oci.dll, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017992672_3_a32691e0e1.jpeg\">\u003C\u002Fp>\u003Cp>calc.exe starts with system privileges\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017996441_4_babee811c6.jpeg\">\u003C\u002Fp>\u003Cp>In actual testing, this method occasionally has bugs; after ending the process via taskkill, msdtc.exe does not restart\u003C\u002Fp>\u003Cp>\u003Cstrong>Solution:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Simply restart the MSDTC service, command line parameters are as follows:\u003C\u002Fp>\u003Cp>net start msdtc\u003C\u002Fp>\u003Ch2>0x05 More Testing\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Testing on 32-bit systems\u003C\u002Fh3>\u003Cp>For 32-bit systems, simply use the 32-bit dll, download address is as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Ch3>2. Testing 64-bit systems\u003C\u002Fh3>\u003Cp>In 64-bit systems, although the SysWOW64 folder contains the 32-bit msdtc.exe, the MSDTC service only launches the 64-bit msdtc.exe\u003C\u002Fp>\u003Cp>Therefore, loading the 32-bit oci.dll is not supported\u003C\u002Fp>\u003Ch3>3. General testing\u003C\u002Fh3>\u003Cp>Actual testing shows that the MSDTC service is not exclusive to domain environments; it also starts by default in workgroup environments\u003C\u002Fp>\u003Cp>This means the exploitation method is applicable not only to domain environments but also to workgroup environments\u003C\u002Fp>\u003Ch3>4. Loading oci.dll with administrator privileges (privilege reduction startup)\u003C\u002Fh3>\u003Cp>The above method loads oci.dll with system privileges. Here is a method to load oci.dll with administrator privileges (privilege reduction startup):\u003C\u002Fp>\u003Cp>Execute in an administrator command prompt:\u003C\u002Fp>\u003Cp>msdtc -install\u003C\u002Fp>\u003Cp>The launched calc.exe runs with high privileges, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017999418_5_e2b1780688.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>For reasons why privilege reduction is needed and more implementation methods, refer to the article\u003C\u002Fp>\u003Cp>《Penetration Techniques – Privilege Reduction Startup of Programs》\u003C\u002Fp>\u003Ch2>0x06 Detection and Defense\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>Detection:\u003C\u002Fh3>\u003Cp>Check if %windir%\\system32\\ contains suspicious oci.dll\u003C\u002Fp>\u003Ch3>Defense:\u003C\u002Fh3>\u003Cp>For regular user hosts, it is recommended to disable the MSDTC service\u003C\u002Fp>\u003Ch2>0x07 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces exploitation techniques related to MSDTC, which can not only be used as a backdoor but also for launching programs with reduced privileges.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Cp>---\u003C\u002Fp>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>A backdoor previously used by Shadow Force in a domain environment, leveraging the MSDTC service to load a DLL for achieving persistence and bypassing Autoruns' detection of startup items. This article will test it, introduce more exploitation techniques, and analyze defense methods.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Introduction to MSDTC\u003C\u002Fli>\u003Cli>Backdoor Concept\u003C\u002Fli>\u003Cli>Backdoor Verification\u003C\u002Fli>\u003Cli>More Testing and Exploitation Methods\u003C\u002Fli>\u003Cli>Detection and Defense\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Introduction to MSDTC\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>MSDTC:\u003C\u002Fh3>\u003Cul>\u003Cli>Corresponding service MSDTC, full name Distributed Transaction Coordinator, this service is started by default in Windows systems\u003C\u002Fli>\u003Cli>Corresponding process msdtc.exe, located at %windir%\\system32\\\u003C\u002Fli>\u003Cli>msdtc.exe is the Microsoft Distributed Transaction Coordinator, this process invokes the system's Microsoft Personal Web Server and Microsoft SQL Server\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x03 Backdoor Concept\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>\u003Cstrong>Reference link:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>http:\u002F\u002Fblog.trendmicro.com\u002Ftrendlabs-security-intelligence\u002Fshadow-force-uses-dll-hijacking-targets-south-korean-company\u002F\u003C\u002Fp>\u003Cp>The concept introduced in the article is as follows:\u003C\u002Fp>\u003Cp>When a computer joins a domain and the MSDTC service starts, it searches the registry HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\MSDTC\\MTxOCI\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017971471_0_366ce87e92-1.jpeg\">\u003C\u002Fp>\u003Cp>It loads three DLLs respectively: oci.dll, SQLLib80.dll, xa80.dll\u003C\u002Fp>\u003Cp>However, notably,\u003Cstrong>Windows systems do not include oci.dll by default\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>That is to say, rename payload.dll to oci.dll and save it under %windir%\\system32\\\u003C\u002Fp>\u003Cp>When the MSDTC service starts on computers in the domain, it will load this dll to achieve code execution\u003C\u002Fp>\u003Ch2>0x04 Backdoor Verification\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Test System: Win7 x64\u003C\u002Fp>\u003Cp>Set up the domain environment, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017982877_1_6f1aec569e-1.jpeg\">\u003C\u002Fp>\u003Cp>Use Procmon to monitor the startup process of msdtc, filter the process msdtc.exe, and view file operations, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017987633_2_ae678245f6-1.jpeg\">\u003C\u002Fp>\u003Cp>msdtc.exe does indeed attempt to load oci.dll, and since oci.dll does not exist by default in the system, the loading fails\u003C\u002Fp>\u003Cp>Use a 64-bit test dll, download link as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Save it under %windir%\\system32\\\u003C\u002Fp>\u003Cp>Terminate the process msdtc.exe, command line parameters as follows:\u003C\u002Fp>\u003Cp>taskkill \u002Ff \u002Fim msdtc.exe\u003C\u002Fp>\u003Cp>Waiting for msdtc.exe to restart\u003C\u002Fp>\u003Cp>After waiting for a while, mstdc.exe restarts and successfully loads oci.dll, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017992672_3_a32691e0e1-1.jpeg\">\u003C\u002Fp>\u003Cp>calc.exe starts with system privileges\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017996441_4_babee811c6-1.jpeg\">\u003C\u002Fp>\u003Cp>In actual testing, this method occasionally has bugs; after ending the process via taskkill, msdtc.exe does not restart\u003C\u002Fp>\u003Cp>\u003Cstrong>Solution:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Simply restart the MSDTC service, command line parameters are as follows:\u003C\u002Fp>\u003Cp>net start msdtc\u003C\u002Fp>\u003Ch2>0x05 More Testing\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Testing on 32-bit systems\u003C\u002Fh3>\u003Cp>For 32-bit systems, simply use the 32-bit dll, download address is as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Ch3>2. Testing 64-bit systems\u003C\u002Fh3>\u003Cp>In 64-bit systems, although the SysWOW64 folder contains the 32-bit msdtc.exe, the MSDTC service only launches the 64-bit msdtc.exe\u003C\u002Fp>\u003Cp>Therefore, loading the 32-bit oci.dll is not supported\u003C\u002Fp>\u003Ch3>3. General testing\u003C\u002Fh3>\u003Cp>Actual testing shows that the MSDTC service is not exclusive to domain environments; it also starts by default in workgroup environments\u003C\u002Fp>\u003Cp>This means the exploitation method is applicable not only to domain environments but also to workgroup environments\u003C\u002Fp>\u003Ch3>4. Loading oci.dll with administrator privileges (privilege reduction startup)\u003C\u002Fh3>\u003Cp>The above method loads oci.dll with system privileges. Here is a method to load oci.dll with administrator privileges (privilege reduction startup):\u003C\u002Fp>\u003Cp>Execute in an administrator command prompt:\u003C\u002Fp>\u003Cp>msdtc -install\u003C\u002Fp>\u003Cp>The launched calc.exe runs with high privileges, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017999418_5_e2b1780688-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>For reasons why privilege reduction is needed and more implementation methods, refer to the article\u003C\u002Fp>\u003Cp>《Penetration Techniques – Privilege Reduction Startup of Programs》\u003C\u002Fp>\u003Ch2>0x06 Detection and Defense\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>Detection:\u003C\u002Fh3>\u003Cp>Check if %windir%\\system32\\ contains suspicious oci.dll\u003C\u002Fp>\u003Ch3>Defense:\u003C\u002Fh3>\u003Cp>For regular user hosts, it is recommended to disable the MSDTC service\u003C\u002Fp>\u003Ch2>0x07 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces exploitation techniques related to MSDTC, which can not only be used as a backdoor but also for launching programs with reduced privileges.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",1115,"Onedaysec",3,"published","2026-02-02T07:51:00.067Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"MSDTC Backdoor: Persistence via DLL Hijacking & Defense","MSDTC backdoor, DLL hijacking, persistence, Windows security, domain environment, detection, defense, Shadow Force, oci.dll",null,false,[],{"docs":43,"hasNextPage":40},[44,4,45,46,47],470,468,467,466,{"title":39,"description":39,"image":39},"2026-07-24T15:37:13.150Z","2026-07-23T16:01:37.818Z","draft","2026-07-23T16:12:33.247Z"]