ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1218.011×

69 examples

TechniqueUsed byProcedure example
T1218.011
Rundll32
MalwareFunnyDream

FunnyDream can use `rundll32` for execution of its components.

T1218.011
Rundll32
MalwareKwampirs

Kwampirs uses rundll32.exe in a Registry value added to establish persistence.

T1218.011
Rundll32
MalwareBoomBox

BoomBox can use RunDLL32 for execution.

T1218.011
Rundll32
MalwareDEADEYE

DEADEYE can use `rundll32.exe` for execution of living off the land binaries (lolbin) such as `SHELL32.DLL`.

T1218.011
Rundll32
MalwareEgregor

Egregor has used rundll32 during execution.

T1218.011
Rundll32
MalwareFELIXROOT

FELIXROOT uses Rundll32 for executing the dropper program.

T1218.011
Rundll32
MalwareZxShell

ZxShell has used rundll32.exe to execute other DLLs and named pipes.

T1218.011
Rundll32
MalwareDDKONG

DDKONG uses Rundll32 to ensure only a single instance of itself is running at once.

T1218.011
Rundll32
MalwareWinnti for Windows

The Winnti for Windows installer loads a DLL using rundll32.

T1218.011
Rundll32
MalwareTroll Stealer

Troll Stealer is dropped as a DLL file and executed via `rundll32.exe` by its installer.

T1218.011
Rundll32
MalwareHeyoka Backdoor

Heyoka Backdoor can use rundll32.exe to gain execution.

T1218.011
Rundll32
MalwareCozyCar

The CozyCar dropper copies the system file rundll32.exe to the install location for the malware, then uses the copy of rundll32.exe to load and execute the main CozyCar component.

T1218.011
Rundll32
MalwareQakBot

QakBot has used Rundll32.exe to drop malicious DLLs including Brute Ratel C4 and to enable C2 communication.

T1218.011
Rundll32
MalwareComnie

Comnie uses Rundll32 to load a malicious DLL.

T1218.011
Rundll32
MalwareADVSTORESHELL

ADVSTORESHELL has used rundll32.exe in a Registry value to establish persistence.

T1218.011
Rundll32
MalwareHermeticWizard

HermeticWizard has the ability to create a new process using `rundll32`.

T1218.011
Rundll32
ToolPcShare

PcShare has used `rundll32.exe` for execution.

T1218.011
Rundll32
ToolKoadic

Koadic can use Rundll32 to execute additional payloads.

T1218.011
Rundll32
MalwareFlame

Rundll32.exe is used as a way of executing Flame at the command-line.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.