ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1218.010×

23 examples

TechniqueUsed byProcedure example
T1218.010
Regsvr32
MalwareOrz

Some Orz versions have an embedded DLL known as MockDll that uses Process Hollowing and regsvr32 to execute another payload.

T1218.010
Regsvr32
MalwareTONESHELL

TONESHELL has used regsvr32.exe to execute the windows `DLLRegisterServer` function.

T1218.010
Regsvr32
MalwareAppleSeed

AppleSeed can call regsvr32.exe for execution.

T1218.010
Regsvr32
MalwareEmotet

Emotet uses RegSvr32 to execute the DLL payload.

T1218.010
Regsvr32
MalwareSquirrelwaffle

Squirrelwaffle has been executed using `regsvr32.exe`.

T1218.010
Regsvr32
MalwareRaspberry Robin

Raspberry Robin uses regsvr32.exe execution without any command line parameters for command and control requests to IP addresses associated with Tor nodes.

T1218.010
Regsvr32
MalwareRagnar Locker

Ragnar Locker has used regsvr32.exe to execute components of VirtualBox.

T1218.010
Regsvr32
MalwareHi-Zor

Hi-Zor executes using regsvr32.exe called from the Registry Run Keys / Startup Folder persistence mechanism.

T1218.010
Regsvr32
MalwareXbash

Xbash can use regsvr32 for executing scripts.

T1218.010
Regsvr32
MalwareSaint Bot

Saint Bot has used `regsvr32` to execute scripts.

T1218.010
Regsvr32
MalwareEVILNUM

EVILNUM can run a remote scriptlet that drops a file and executes it via regsvr32.exe.

T1218.010
Regsvr32
MalwareMori

Mori can use `regsvr32.exe` for DLL execution.

T1218.010
Regsvr32
MalwareRogueRobin

RogueRobin uses regsvr32.exe to run a .sct file for execution.

T1218.010
Regsvr32
MalwareDerusbi

Derusbi variants have been seen that use Registry persistence to proxy execution through regsvr32.exe.

T1218.010
Regsvr32
MalwareValak

Valak has used regsvr32.exe to launch malicious DLLs.

T1218.010
Regsvr32
MalwareMore_eggs

More_eggs has used regsvr32.exe to execute the malicious DLL.

T1218.010
Regsvr32
MalwareEgregor

Egregor has used regsvr32.exe to execute malicious DLLs.

T1218.010
Regsvr32
MalwareAstaroth

Astaroth can be loaded through regsvr32.exe.

T1218.010
Regsvr32
MalwareQakBot

QakBot can use Regsvr32 to execute malicious DLLs.

T1218.010
Regsvr32
MalwareDridex

Dridex can use `regsvr32.exe` to initiate malicious code.

T1218.010
Regsvr32
MalwareHermeticWizard

HermeticWizard has used `regsvr32.exe /s /i` to execute malicious payloads.

T1218.010
Regsvr32
ToolCovenant

Covenant can create SCT files for installation via `Regsvr32` to deploy new Grunt listeners.

T1218.010
Regsvr32
ToolKoadic

Koadic can use Regsvr32 to execute additional payloads.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.