Potential Persistence Via Scrobj.dll COM Hijacking

 Original Source: [Sigma source]
Title: Potential Persistence Via Scrobj.dll COM Hijacking
Status: test
Description:Detect use of scrobj.dll as this DLL looks for the ScriptletURL key to get the location of the script to execute
References:
  -https://github.com/redcanaryco/atomic-red-team/blob/40b77d63808dd4f4eafb83949805636735a1fd15/atomics/T1546.015/T1546.015.md
Author: frack113
Date: 2022-08-20
modified:2023-08-17
Tags:
  • -'attack.privilege-escalation'
  • -'attack.persistence'
  • -'attack.t1546.015'
Logsource:
  • category: registry_set
  • product: windows
Detection:
  selection:
    TargetObject|endswith: 'InprocServer32\(Default)'
    Details: 'C:\WINDOWS\system32\scrobj.dll'
  condition:selection
Falsepositives:
  -Legitimate use of the dll.
Level: medium