Regsvr32

T1218.010

Sub-technique of T1218 System Binary Proxy Execution.View on attack.mitre.org

About this technique

Adversaries may abuse Regsvr32.exe to proxy execution of malicious code. Regsvr32.exe is a command-line program used to register and unregister object linking and embedding controls, including dynamic link libraries (DLLs), on Windows systems. The Regsvr32.exe binary may also be signed by Microsoft.

Malicious usage of Regsvr32.exe may avoid triggering security tools that may not monitor execution of, and modules loaded by, the regsvr32.exe process because of allowlists or false positives from Windows using regsvr32.exe for normal operations. Regsvr32.exe can also be used to specifically bypass application control using functionality to load COM scriptlets to execute DLLs under user permissions. Since Regsvr32.exe is network and proxy aware, the scripts can be loaded by passing a uniform resource locator (URL) to file on an external Web server as an argument during invocation. This method makes no changes to the Registry as the COM object is not actually registered, only executed. This variation of the technique is often referred to as a "Squiblydoo" and has been used in campaigns targeting governments.

Regsvr32.exe can also be leveraged to register a COM Object used to establish persistence via Component Object Model Hijacking.

Detection rules24

Rules on DetectionCode tagged with T1218.010.

Sigma17

RuleLevelLog source
HTML Help HH.EXE Suspicious Child Processhighwindows / process_creation
Potentially Suspicious Child Process Of Regsvr32highwindows / process_creation
Potentially Suspicious Regsvr32 HTTP IP Patternhighwindows / process_creation
Regsvr32 DLL Execution With Suspicious File Extensionhighwindows / process_creation
Regsvr32 Execution From Highly Suspicious Locationhighwindows / process_creation
Suspicious HH.EXE Executionhighwindows / process_creation
Suspicious Microsoft Office Child Processhighwindows / process_creation
Suspicious Regsvr32 Execution From Remote Sharehighwindows / process_creation
Suspicious WMIC Execution Via Office Processhighwindows / process_creation
Suspicious WmiPrvSE Child Processhighwindows / process_creation
DNS Query Request By Regsvr32.EXEmediumwindows / dns_query
Network Connection Initiated By Regsvr32.EXEmediumwindows / network_connection
Potential Regsvr32 Commandline Flag Anomalymediumwindows / process_creation
Potentially Suspicious Regsvr32 HTTP/FTP Patternmediumwindows / process_creation
Regsvr32 Execution From Potential Suspicious Locationmediumwindows / process_creation

Splunk7

RuleTypeRiskData source
Detect Regsvr32 Application Control BypassTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Malicious InProcServer32 ModificationTTPNULLSysmon EventID 12, Sysmon EventID 13
Regsvr32 Silent and Install Param Dll LoadingAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Regsvr32 with Known Silent Switch CmdlineAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Suspicious Regsvr32 Register Suspicious PathTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows IOBit Unlocker Extension DLL Registration via Regsvr32TTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows Regsvr32 Renamed BinaryTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2

Groups11

Software23

Campaigns2

Procedure examples36

Groups11

Used byProcedure example
GroupAPT19

APT19 used Regsvr32 to bypass application control techniques.

GroupAPT32

APT32 created a Scheduled Task/Job that used regsvr32.exe to execute a COM scriptlet that dynamically downloaded a backdoor and injected it into memory. The group has also used regsvr32 to run their backdoor.

GroupBlue Mockingbird

Blue Mockingbird has executed custom-compiled XMRIG miner DLLs using regsvr32.exe.

GroupCobalt Group

Cobalt Group has used regsvr32.exe to execute scripts.

GroupDeep Panda

Deep Panda has used regsvr32.exe to execute a server variant of Derusbi in victim networks.

GroupInception

Inception has ensured persistence at system boot by setting the value regsvr32 %path%\ctfmonrn.dll /s.

GroupKimsuky

Kimsuky has executed malware with regsvr32s.

GroupLeviathan

Leviathan has used regsvr32 for execution.

View all 11 groups examples

Software23

Used byProcedure example
MalwareAppleSeed

AppleSeed can call regsvr32.exe for execution.

MalwareAstaroth

Astaroth can be loaded through regsvr32.exe.

ToolCovenant

Covenant can create SCT files for installation via `Regsvr32` to deploy new Grunt listeners.

MalwareDerusbi

Derusbi variants have been seen that use Registry persistence to proxy execution through regsvr32.exe.

MalwareDridex

Dridex can use `regsvr32.exe` to initiate malicious code.

MalwareEgregor

Egregor has used regsvr32.exe to execute malicious DLLs.

MalwareEmotet

Emotet uses RegSvr32 to execute the DLL payload.

MalwareEVILNUM

EVILNUM can run a remote scriptlet that drops a file and executes it via regsvr32.exe.

View all 23 software examples

Campaigns2

Used byProcedure example
CampaignC0015

During C0015, the threat actors employed code that used `regsvr32` for execution.

CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group used `regsvr32` to execute malware.

References4

  1. Carbon Black Squiblydoo Apr 2016 Open source
    Nolen, R. et al.. (2016, April 28). Threat Advisory: “Squiblydoo” Continues Trend of Attackers Using Native OS Tools to “Live off the Land”. Retrieved April 9, 2018.
  2. FireEye Regsvr32 Targeting Mongolian Gov Open source
    Anubhav, A., Kizhakkinan, D. (2017, February 22). Spear Phishing Techniques Used in Attacks Targeting the Mongolian Government. Retrieved February 24, 2017.
  3. LOLBAS Regsvr32 Open source
    LOLBAS. (n.d.). Regsvr32.exe. Retrieved July 31, 2019.
  4. Microsoft Regsvr32 Open source
    Microsoft. (2015, August 14). How to use the Regsvr32 tool and troubleshoot Regsvr32 error messages. Retrieved June 22, 2016.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.