What is the “DLLHOST.EXE” Process Actually Running

Image for post
Image for post
dllhost.exe

“What is the DLLHOST.EXE process actually running”

Component Object Model (COM)

Image for post
Image for post
https://networkencyclopedia.com/wp-content/uploads/2019/09/component-object-model-com.gif
HKEY_CLASSES_ROOT/CLSID/{GUID}
“HKEY_LOCAL_MACHINE\Software\Classes” 
“HKEY_CURRENT_USER\Software\Classes”
Image for post
Image for post
COM Object Example Request

COM Registry Keys (CLSID / ProgID / AppID)

CLSID

ProgID

AppId

Image for post
Image for post
Image for post
Image for post
Image for post
Image for post

DLL Surrogate

COM Surrogate (DLLHOST.EXE)

Image for post
Image for post
Image for post
Image for post

DLLHOST & Malware

Written by

#ThreatHunting #WindowsInternals #Malware #DFIR and occasionally #Python.

Get the Medium app

A button that says 'Download on the App Store', and if clicked it will lead you to the iOS App store
A button that says 'Get it on, Google Play', and if clicked it will lead you to the Google Play store