LoFP LoFP / legitimate use of the dll.

Techniques

Sample rules

Potential Persistence Via Scrobj.dll COM Hijacking

Description

Detect use of scrobj.dll as this DLL looks for the ScriptletURL key to get the location of the script to execute

Detection logic

condition: selection
selection:
  Details: C:\WINDOWS\system32\scrobj.dll
  TargetObject|endswith: InprocServer32\(Default)