Possible code downloading from a remote host by Regsvr32
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent
Detector Tags
LOLBIN Execution Analytics
ATT&CK Tactic
Stealth (TA0005)
ATT&CK Technique
System Binary Proxy Execution: Regsvr32 (T1218.010)
Severity
Medium
Description
Regsvr32 may be used to fetch arbitrary code from a remote host and execute it without dropping the payload onto the disk. Known to be used for malicious purposes.
Attacker's Goals
Gain code execution on the host and evade security controls.
Investigative actions
Check whether the executing process is benign and if this was a desired behavior as part of its normal execution flow.
PreviousPossible brute force or configuration change attempt on cytool
NextPossible collection of screen captures with Windows Problem Steps Recorder
Was this helpful?
