{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,5]],"date-time":"2026-06-05T04:38:01Z","timestamp":1780634281412,"version":"3.54.1"},"reference-count":69,"publisher":"MDPI AG","issue":"16","license":[{"start":{"date-parts":[[2024,8,7]],"date-time":"2024-08-07T00:00:00Z","timestamp":1722988800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>Behavioral malware detection is based on attributing malicious actions to processes. Malicious processes may try to hide by changing the behavior of other benign processes to achieve their goals. We showcase how Component Object Model (COM) and Windows Management Instrumentation (WMI) can be used to create such spoofing attacks. We discuss the internals of COM and WMI and Asynchronous Local Procedure Call (ALPC). We present multiple functional monitoring techniques to identify the spoofing and discuss the strong and weak points of each technique. We create a robust process monitoring system that can correctly identify the source of malicious actions spoofed via COM, WMI and ALPC with a low performance impact. Finally, we discuss how malicious actors use COM, WMI and ALPC by examining real-world malware detected by our monitoring system.<\/jats:p>","DOI":"10.3390\/s24165118","type":"journal-article","created":{"date-parts":[[2024,8,8]],"date-time":"2024-08-08T07:01:25Z","timestamp":1723100485000},"page":"5118","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":6,"title":["Detection Strategies for COM, WMI, and ALPC-Based Multi-Process Malware"],"prefix":"10.3390","volume":"24","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-9008-1462","authenticated-orcid":false,"given":"Radu Marian","family":"Portase","sequence":"first","affiliation":[{"name":"Computer Science Department, Technical University of Cluj Napoca, 400114 Cluj Napoca, Romania"},{"name":"Bitdefender, 060071 Bucharest, Romania"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Andrei Marius","family":"Muntea","sequence":"additional","affiliation":[{"name":"Computer Science Department, Technical University of Cluj Napoca, 400114 Cluj Napoca, Romania"},{"name":"Bitdefender, 060071 Bucharest, Romania"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Andrei","family":"Mermeze","sequence":"additional","affiliation":[{"name":"Computer Science Department, Technical University of Cluj Napoca, 400114 Cluj Napoca, Romania"},{"name":"Bitdefender, 060071 Bucharest, Romania"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2431-4253","authenticated-orcid":false,"given":"Adrian","family":"Colesa","sequence":"additional","affiliation":[{"name":"Computer Science Department, Technical University of Cluj Napoca, 400114 Cluj Napoca, Romania"},{"name":"Bitdefender, 060071 Bucharest, Romania"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7773-1077","authenticated-orcid":false,"given":"Gheorghe","family":"Sebestyen","sequence":"additional","affiliation":[{"name":"Computer Science Department, Technical University of Cluj Napoca, 400114 Cluj Napoca, Romania"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2024,8,7]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","unstructured":"Miloslavskaya, N. (2016, January 22\u201324). Security Operations Centers for Information Security Incident Management. Proceedings of the 2016 IEEE 4th International Conference on Future Internet of Things and Cloud (FiCloud), Vienna, Austria.","DOI":"10.1109\/FiCloud.2016.26"},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"35","DOI":"10.1109\/MSP.2014.103","article-title":"The Operational Role of Security Information and Event Management Systems","volume":"12","author":"Bhatt","year":"2014","journal-title":"IEEE Secur. Priv."},{"key":"ref_3","unstructured":"Chuvakin, A. (2024, June 15). Named: Endpoint Threat Detection & Response. Available online: https:\/\/blogs.gartner.com\/anton-chuvakin\/2013\/07\/26\/named-endpoint-threat-detection-response\/."},{"key":"ref_4","doi-asserted-by":"crossref","unstructured":"Rieck, K., Holz, T., Willems, C., D\u00fcssel, P., and Laskov, P. (2008). Learning and Classification of Malware Behavior. Detection of Intrusions and Malware, and Vulnerability Assessment, Springer.","DOI":"10.1007\/978-3-540-70542-0_6"},{"key":"ref_5","unstructured":"Microsoft (2024, June 15). MSDN:\u00a0Component Object Model. Available online: https:\/\/docs.microsoft.com\/en-us\/windows\/win32\/com\/component-object-model--com--portal."},{"key":"ref_6","unstructured":"Microsoft (2024, June 15). MSDN:\u00a0Windows Management Instrumentation. Available online: https:\/\/docs.microsoft.com\/en-us\/windows\/win32\/wmisdk\/wmi-start-page."},{"key":"ref_7","unstructured":"Ballenthinm, W., Graeber, M., and Teodorescu, C. (2015). Windows Management Instrumentation (WMI) Offense, Defense, and Forensics. FireEye White Paper, Federal News Network."},{"key":"ref_8","unstructured":"Allievi, A., Ionescu, A., Russinovich, M.E., and Solomon, D.A. (2021). Windows Internals, Part 2, Microsoft Press. [7th ed.]."},{"key":"ref_9","unstructured":"(2024, June 15). Github Repository:\u00a0Koadic. Available online: https:\/\/github.com\/offsecginger\/koadic."},{"key":"ref_10","unstructured":"Schroeder, W., and Warner, J. (2024, June 15). Github Repository:\u00a0Empire Project. Available online: https:\/\/github.com\/EmpireProject."},{"key":"ref_11","unstructured":"Microsoft (2024, June 15). MSDN:\u00a0Win32_Process Class. Available online: https:\/\/learn.microsoft.com\/en-us\/previous-versions\/windows\/desktop\/krnlprov\/win32-processstarttrace."},{"key":"ref_12","unstructured":"Schroeder, W., and Warner, J. (2024, June 15). Github Repository:\u00a0Empire Project Invoje-ExecuteMSBuild. Available online: https:\/\/github.com\/EmpireProject\/Empire."},{"key":"ref_13","unstructured":"(2024, June 15). Vault 7:\u00a0CIA Hacking Tools Revealed: WMI in C++ via WbemScripting. Available online: https:\/\/wikileaks.org\/ciav7p1\/cms\/page_13763881.html."},{"key":"ref_14","unstructured":"Matrosov, A., Rodionov, E., Harley, D., and Malcho, J. (2011). Stuxnet Under the Microscope. Eset White Paper, ESET."},{"key":"ref_15","unstructured":"0xffsec (2024, June 15). MSRPC (Microsoft Remote Procedure Call) Service Enumeration. 0xffsec Handbook. Available online: https:\/\/0xffsec.com\/handbook\/services\/msrpc\/."},{"key":"ref_16","unstructured":"SpecterOps (2024, June 15). Offensive Lateral Movement. SpecterOps. Available online: https:\/\/posts.specterops.io\/offensive-lateral-movement-1744ae62b14f."},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Ji, Y., He, Y., Zhu, D., Li, Q., and Guo, D. (2014, January 5\u20138). A Mulitiprocess Mechanism of Evading Behavior-Based Bot Detection Approaches. Proceedings of the 10th International Conference on Information Security Practice and Experience\u2014Volume 8434, Fuzhou, China.","DOI":"10.1007\/978-3-319-06320-1_7"},{"key":"ref_18","unstructured":"Ispoglou, K.K., and Payer, M. (2016, January 8\u20139). malWASH: Washing Malware to Evade Dynamic Analysis. Proceedings of the 10th USENIX Workshop on Offensive Technologies (WOOT 16), Austin, TX, USA."},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1007\/s11416-011-0157-5","article-title":"Shadow attacks: Automatically evading system-call-behavior based malware detection","volume":"8","author":"Ma","year":"2012","journal-title":"J. Comput. Virol."},{"key":"ref_20","unstructured":"Thompson, D., Exton, C., Garrett, L., Sajeev, A., and Watkins, D. (1997). Distributed Component Object Model (DCOM), Department of Software Development, Faculty of Computing and Information Technology, Monash University. Technical Report."},{"key":"ref_21","unstructured":"Eddon, G.R., and Eddon, H. (1999). Inside Com+: Base Services with Cdrom, Microsoft Press."},{"key":"ref_22","unstructured":"Forshaw, J. (2024, June 15). COM in 60 Seconds! 2017. Online course. Available online: https:\/\/youtu.be\/dfMuzAZRGm4?si=loa1xLvQZReZIfSH."},{"key":"ref_23","unstructured":"Strom, B., and Ewing, P. (2024, June 15). How To Hunt: Detecting Persistence & Evasion with COM. Available online: https:\/\/www.elastic.co\/blog\/how-hunt-detecting-persistence-evasion-com."},{"key":"ref_24","first-page":"49","article-title":"Building a Lightweight COM Interception Framework, Part II: The Guts of the UD","volume":"14","author":"Brown","year":"1999","journal-title":"Microsoft Syst. J."},{"key":"ref_25","first-page":"17","article-title":"Building a Lightweight COM Interception Framework, Part 1: The Universal Delegator","volume":"14","author":"Brown","year":"1999","journal-title":"Microsoft Syst. J."},{"key":"ref_26","first-page":"46","article-title":"A Review on Fileless Malware Analysis Techniques","volume":"9","author":"Vala","year":"2020","journal-title":"Int. J. Eng. Res. Technol. (IJERT)"},{"key":"ref_27","unstructured":"Graeber, M. (2015, January 1\u20136). Abusing Windows Management Instrumentation (WMI) to Build a Persistent, Asynchronous, and Fileless Backdoor. Proceedings of the Black Hat USA, Las Vegas, NV, USA."},{"key":"ref_28","unstructured":"Dizon, J., Galang, L., and Cruz, M. (2024, June 15). Understanding WMI Malware. Technical Report, Trend Micro. Available online: https:\/\/carriersnc.com\/Virus_Help_7\/understanding-wmi-malware-research-paper-en.pdf."},{"key":"ref_29","unstructured":"SANS (2024, June 15). Investigating WMI Attacks. Available online: https:\/\/www.sans.org\/blog\/investigating-wmi-attacks\/."},{"key":"ref_30","unstructured":"Ionescu, I.A. (2021). Rpc Call Interception. (US20150163109A1), U.S. Patent, Available online: https:\/\/patents.google.com\/patent\/US20150163109A1\/en."},{"key":"ref_31","unstructured":"Ionescu, I.A., Kreuzer, T., and LeMasters, A. (2019). Tracing System Operations across Remote Procedure Linkages to Identify Request Originators. (10,191,789), U.S. Patent, Available online: https:\/\/scholar.google.com\/citations?view_op=view_citation&hl=en&user=tcIYPucAAAAJ&citation_for_view=tcIYPucAAAAJ:d1gkVwhDpl0C."},{"key":"ref_32","unstructured":"Stanciu, A., Anton, T., Enachescu, A., and Clyde, R.A. (2023). Detecting Malware by Linking Background Intelligent Transfer Service (BITS) and Scheduled Task Service (STS) Activities to a Source Program. (11,727,111), U.S. Patent, Available online: https:\/\/portal.unifiedpatents.com\/patents\/patent\/US-20130346444-A1."},{"key":"ref_33","unstructured":"Microsoft (2024, June 15). Connecting to the BITS Service. Available online: https:\/\/learn.microsoft.com\/en-us\/windows\/win32\/bits\/connecting-to-the-bits-service."},{"key":"ref_34","doi-asserted-by":"crossref","unstructured":"Hajmasan, G., Mondoc, A., Portase, R., and Cre\u0163, O. (2017, January 29\u201331). Evasive Malware Detection Using Groups of Processes. Proceedings of the ICT Systems Security and Privacy Protection, Rome, Italy.","DOI":"10.1007\/978-3-319-58469-0_3"},{"key":"ref_35","unstructured":"Microsoft (2024, June 15). MSDN:\u00a0File System Minifilter Drivers. Available online: https:\/\/docs.microsoft.com\/en-us\/windows-hardware\/drivers\/ifs\/file-system-minifilter-drivers."},{"key":"ref_36","unstructured":"(2024, June 15). CodeMachine:\u00a0Kernel Callback Functions. Available online: https:\/\/codemachine.com\/articles\/kernel_callback_functions.html."},{"key":"ref_37","unstructured":"Microsoft (2024, June 15). MSDN:\u00a0Windows Filtering Platform. Available online: https:\/\/docs.microsoft.com\/en-us\/windows\/win32\/fwp\/windows-filtering-platform-start-page."},{"key":"ref_38","unstructured":"Microsoft (2024, June 15). MSDN:\u00a0Event Tracing. Available online: https:\/\/docs.microsoft.com\/en-us\/windows\/win32\/etw\/event-tracing-portal."},{"key":"ref_39","unstructured":"Microsoft (2024, June 15). MSDN:\u00a0Enhanced Mitigation Experience Toolkit. Available online: https:\/\/support.microsoft.com\/en-us\/help\/2458544\/the-enhanced-mitigation-experience-toolkit."},{"key":"ref_40","unstructured":"Microsoft (2024, June 15). MSDN:\u00a0Application Compatibility Toolkit. Available online: https:\/\/docs.microsoft.com\/en-us\/windows\/deployment\/planning\/act-technical-reference."},{"key":"ref_41","unstructured":"Microsoft (2024, June 15). MSDN:\u00a0IFileOperation Interface. Available online: https:\/\/docs.microsoft.com\/en-us\/windows\/win32\/api\/shobjidl_core\/nn-shobjidl_core-ifileoperation."},{"key":"ref_42","unstructured":"Microsoft (2024, June 15). MSDN:\u00a0COM API for WMI. Available online: https:\/\/docs.microsoft.com\/en-us\/windows\/win32\/wmisdk\/com-api-for-wmi."},{"key":"ref_43","unstructured":"Microsoft (2024, June 15). MSDN:\u00a0StdRegProv Class. Available online: https:\/\/docs.microsoft.com\/en-us\/previous-versions\/windows\/desktop\/regprov\/stdregprov."},{"key":"ref_44","unstructured":"Microsoft (2024, June 15). Process\u00a0Monitor. Available online: https:\/\/learn.microsoft.com\/en-us\/sysinternals\/downloads\/procmon."},{"key":"ref_45","unstructured":"Hunt, G., and Scott, M.L. (1999, January 3\u20137). Intercepting and Instrumenting COM Applications. Proceedings of the Fifth Conference on Object-Oriented Technologies and Systems (COOTS), USENIX, San Diego, CA, USA."},{"key":"ref_46","unstructured":"Microsoft (2024, June 15). MSDN:\u00a0IUnknown Interface. Available online: https:\/\/docs.microsoft.com\/en-us\/windows\/win32\/api\/unknwn\/nn-unknwn-iunknown."},{"key":"ref_47","unstructured":"Microsoft (2024, June 15). MSDN:\u00a0GUID Structure. Available online: https:\/\/docs.microsoft.com\/en-us\/windows\/win32\/api\/guiddef\/ns-guiddef-guid."},{"key":"ref_48","unstructured":"Microsoft (2024, June 15). MSDN:\u00a0IClassFactory Interface. Available online: https:\/\/docs.microsoft.com\/en-us\/windows\/win32\/api\/unknwn\/nn-unknwn-iclassfactory."},{"key":"ref_49","unstructured":"Microsoft (2024, June 15). MSDN:\u00a0CoGetClassObject Function. Available online: https:\/\/docs.microsoft.com\/en-us\/windows\/win32\/api\/combaseapi\/nf-combaseapi-cogetclassobject."},{"key":"ref_50","unstructured":"Microsoft (2024, June 15). MSDN:\u00a0CoCreateInstanceEx Function. Available online: https:\/\/docs.microsoft.com\/en-us\/windows\/win32\/api\/combaseapi\/nf-combaseapi-cocreateinstanceex."},{"key":"ref_51","unstructured":"Microsoft (2024, June 15). MSDN:\u00a0COM Clients and Servers. Available online: https:\/\/docs.microsoft.com\/en-us\/windows\/win32\/com\/com-clients-and-servers."},{"key":"ref_52","unstructured":"Microsoft (2024, June 15). MSDN:\u00a0DllGetClassObject Function. Available online: https:\/\/docs.microsoft.com\/en-us\/windows\/win32\/api\/combaseapi\/nf-combaseapi-dllgetclassobject."},{"key":"ref_53","unstructured":"Microsoft (2024, June 15). MSDN:\u00a0Proxy. Available online: https:\/\/docs.microsoft.com\/en-us\/windows\/win32\/com\/proxy."},{"key":"ref_54","unstructured":"Microsoft (2024, June 15). MSDN:\u00a0Stub. Available online: https:\/\/docs.microsoft.com\/en-us\/windows\/win32\/com\/stub."},{"key":"ref_55","unstructured":"Microsoft (2007). MSDN Blogs:\u00a0LPC (Local Procedure Calls) Part 1 Architecture, Microsoft. Available online: http:\/\/blogs.microsoft.co.il\/pavely\/2017\/08\/07\/hooking-com-classes\/."},{"key":"ref_56","unstructured":"Microsoft (2024, June 15). MSDN:\u00a0Receiving Events at All Times. Available online: https:\/\/docs.microsoft.com\/en-us\/windows\/win32\/wmisdk\/receiving-events-at-all-times."},{"key":"ref_57","unstructured":"Microsoft (2024, June 15). MSDN:\u00a0CoTreatAsClass Function. Available online: https:\/\/docs.microsoft.com\/en-us\/windows\/win32\/api\/objbase\/nf-objbase-cotreatasclass."},{"key":"ref_58","unstructured":"Team, B. (2024, June 15). Design Issues of Modern EDRs:\u00a0Bypassing ETW-Based Solutions. Available online: https:\/\/www.binarly.io\/posts\/Design_issues_of_modern_EDR%27s_bypassing_ETW-based_solutions\/index.html."},{"key":"ref_59","unstructured":"Blunden, B. (2012). The Rootkit Arsenal: Escape and Evasion in the Dark Corners of the System, Jones & Bartlett Learning."},{"key":"ref_60","unstructured":"Microsoft (2024, June 15). MSDN:\u00a0ITaskService. Available online: https:\/\/docs.microsoft.com\/en-us\/windows\/win32\/api\/taskschd\/nn-taskschd-itaskservice."},{"key":"ref_61","unstructured":"Microsoft (2024, June 15). MSDN:\u00a0Task Scheduler Scripting Objects. Available online: https:\/\/docs.microsoft.com\/en-us\/windows\/win32\/taskschd\/task-scheduler-objects."},{"key":"ref_62","unstructured":"Microsoft (2024, June 15). User Account\u00a0Control. Available online: https:\/\/docs.microsoft.com\/en-us\/windows\/win32\/secauthz\/user-account-control."},{"key":"ref_63","unstructured":"(2024, June 15). Github Repository: UACMe. Available online: https:\/\/github.com\/hfiref0x\/UACME."},{"key":"ref_64","doi-asserted-by":"crossref","unstructured":"Sebasti\u00e1n, S., and Caballero, J. (2020). AVClass2: Massive Malware Tag Extraction from AV Labels. arXiv.","DOI":"10.1145\/3427228.3427261"},{"key":"ref_65","unstructured":"AV-Test (2024, June 15). AV-Test Test Module\u2014Performance (System Load); AV-Test. Available online: https:\/\/www.av-test.org\/en\/test-procedures\/test-modules\/performance\/."},{"key":"ref_66","unstructured":"Microsoft Support (2024, June 15). Security Settings for COM Objects in Office. Available online: https:\/\/support.microsoft.com\/en-us\/topic\/security-settings-for-com-objects-in-office-b08a031c-0ab8-3796-b8ec-a89f9dbb443d."},{"key":"ref_67","unstructured":"Microsoft Learn (2024, June 15). Starting and Stopping the WMI Service. Available online: https:\/\/learn.microsoft.com\/en-us\/windows\/win32\/wmisdk\/starting-and-stopping-the-wmi-service."},{"key":"ref_68","unstructured":"Microsoft Support (2024, June 15). How to Disable DCOM Support in Windows. Available online: https:\/\/support.microsoft.com\/en-us\/topic\/how-to-disable-dcom-support-in-windows-2bb8c280-9698-7f9c-bf67-2625a5873c7b."},{"key":"ref_69","unstructured":"Microsoft Learn (2024, June 15). Connecting to WMI on a Remote Computer. Available online: https:\/\/learn.microsoft.com\/en-us\/windows\/win32\/wmisdk\/connecting-to-wmi-on-a-remote-computer."}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/24\/16\/5118\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T15:31:48Z","timestamp":1760110308000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/24\/16\/5118"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,8,7]]},"references-count":69,"journal-issue":{"issue":"16","published-online":{"date-parts":[[2024,8]]}},"alternative-id":["s24165118"],"URL":"https:\/\/doi.org\/10.3390\/s24165118","relation":{},"ISSN":["1424-8220"],"issn-type":[{"value":"1424-8220","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,8,7]]}}}