Discovering the Anti-Virus Signature and Bypassing It
ID: 24d12652-5e5c-5e93-b6f1-4389fec07b45
STIX ID: report--24d12652-5e5c-5e93-b6f1-4389fec07b45
Feed Name: TrustedSec blog
This post investigates how Windows Defender detects the regsvr32 /i:http ... scrobj.dll (Squiblydoo) technique and documents a manual methodology to discover the detection signature. The author demonstrates multiple bypasses (renaming the DLL, creating symbolic links, using NTFS Alternate Data Streams, placing the SCT locally, and using bitsadmin to download the payload) with example commands and screenshots, concluding that defenders should consider alternative detection approaches.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
