logo

Discovering the Anti-Virus Signature and Bypassing It

ID: 24d12652-5e5c-5e93-b6f1-4389fec07b45

STIX ID: report--24d12652-5e5c-5e93-b6f1-4389fec07b45

Feed Name: TrustedSec blog

Threat Score
65/100

Date Published: 2025-04-25

Date Updated: 2026-05-01

...
...

This post investigates how Windows Defender detects the regsvr32 /i:http ... scrobj.dll (Squiblydoo) technique and documents a manual methodology to discover the detection signature. The author demonstrates multiple bypasses (renaming the DLL, creating symbolic links, using NTFS Alternate Data Streams, placing the SCT locally, and using bitsadmin to download the payload) with example commands and screenshots, concluding that defenders should consider alternative detection approaches.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.