Real-world descriptions of how a group, tool or campaign used a technique.
69 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1218.011 Rundll32 |
MalwareFunnyDream | FunnyDream can use `rundll32` for execution of its components. |
| T1218.011 Rundll32 |
MalwareKwampirs | Kwampirs uses rundll32.exe in a Registry value added to establish persistence. |
| T1218.011 Rundll32 |
MalwareBoomBox | BoomBox can use RunDLL32 for execution. |
| T1218.011 Rundll32 |
MalwareDEADEYE | DEADEYE can use `rundll32.exe` for execution of living off the land binaries (lolbin) such as `SHELL32.DLL`. |
| T1218.011 Rundll32 |
MalwareEgregor | Egregor has used rundll32 during execution. |
| T1218.011 Rundll32 |
MalwareFELIXROOT | FELIXROOT uses Rundll32 for executing the dropper program. |
| T1218.011 Rundll32 |
MalwareZxShell | ZxShell has used rundll32.exe to execute other DLLs and named pipes. |
| T1218.011 Rundll32 |
MalwareDDKONG | DDKONG uses Rundll32 to ensure only a single instance of itself is running at once. |
| T1218.011 Rundll32 |
MalwareWinnti for Windows | The Winnti for Windows installer loads a DLL using rundll32. |
| T1218.011 Rundll32 |
MalwareTroll Stealer | Troll Stealer is dropped as a DLL file and executed via `rundll32.exe` by its installer. |
| T1218.011 Rundll32 |
MalwareHeyoka Backdoor | Heyoka Backdoor can use rundll32.exe to gain execution. |
| T1218.011 Rundll32 |
MalwareCozyCar | The CozyCar dropper copies the system file rundll32.exe to the install location for the malware, then uses the copy of rundll32.exe to load and execute the main CozyCar component. |
| T1218.011 Rundll32 |
MalwareQakBot | QakBot has used Rundll32.exe to drop malicious DLLs including Brute Ratel C4 and to enable C2 communication. |
| T1218.011 Rundll32 |
MalwareComnie | Comnie uses Rundll32 to load a malicious DLL. |
| T1218.011 Rundll32 |
MalwareADVSTORESHELL | ADVSTORESHELL has used rundll32.exe in a Registry value to establish persistence. |
| T1218.011 Rundll32 |
MalwareHermeticWizard | HermeticWizard has the ability to create a new process using `rundll32`. |
| T1218.011 Rundll32 |
ToolPcShare | PcShare has used `rundll32.exe` for execution. |
| T1218.011 Rundll32 |
ToolKoadic | Koadic can use Rundll32 to execute additional payloads. |
| T1218.011 Rundll32 |
MalwareFlame | Rundll32.exe is used as a way of executing Flame at the command-line. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.