Regsvr32
Adversaries may abuse Regsvr32.exe to proxy execution of malicious code. Regsvr32.exe is a command-line program used to register and unregister object linking and embedding controls, including dynamic link libraries (DLLs), on Windows systems. The Regsvr32.exe binary may also be signed by Microsoft. (Citation: Microsoft Regsvr32) Malicious usage of Regsvr32.exe may avoid triggering security tools that may not monitor execution of, and modules loaded by, the regsvr32.exe process because of allow...
BY SOURCE
PROCEDURES (29)
Auto-extracted: 3 detections for suspicious
Auto-extracted: 3 detections for process creation monitoring
Auto-extracted: 2 detections for download
Auto-extracted: 2 detections for child process
Auto-extracted: 2 detections for network connection monitoring
Auto-extracted: 2 detections for wmi
Auto-extracted: 2 detections for bypass
Auto-extracted: 2 detections for parent process
Auto-extracted: 2 detections for script execution monitoring
Auto-extracted: 2 detections for child process
Auto-extracted: 1 detections for remote
Auto-extracted: 1 detections for office
Auto-extracted: 1 detections for suspicious
Auto-extracted: 1 detections for office
Auto-extracted: 1 detections for remote
Auto-extracted: 1 detections for unusual
Auto-extracted: 1 detections for suspicious
Auto-extracted: 1 detections for module load monitoring
Auto-extracted: 1 detections for general monitoring
Auto-extracted: 1 detections for privilege
Auto-extracted: 1 detections for persist
Auto-extracted: 1 detections for suspicious
Auto-extracted: 1 detections for persist
Auto-extracted: 1 detections for remote
Auto-extracted: 1 detections for privilege
Auto-extracted: 1 detections for unusual
Auto-extracted: 1 detections for parent process
Auto-extracted: 1 detections for download
Auto-extracted: 1 detections for privilege