New Abuse of the ClickOnce Technology, Part 1: The Inner Workings of ClickOnce Application Deployment
ID: 74e3fd20-33c6-5148-8d35-15c3f15f0af6
STIX ID: report--74e3fd20-33c6-5148-8d35-15c3f15f0af6
Feed Name: Crowdstrike Blog
This report analyzes the internals of ClickOnce deployments, explaining how rundll32.exe calls dfshim.dll which locates and loads dfdll.dll (via GetRequestedRuntimeInfo), how dfdll!ActivateDeploymentW invokes InvokeServer/BindToServer to initialize the COM server (using CoCreateInstance with a specific CLSID) and may launch dfsvc.exe, and why dfshim.dll acts as an intermediate between System32 and .NET runtime libraries; the focus is on normal deployment mechanics rather than malicious activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
