Image for post
Image for post
Rundll32

RUNDLL32.EXE

rundll32 <DLLname>
\Windows\System32\rundll32.exe
\Windows\SysWOW64\rundll32.exe (32bit version on 64bit systems)

Running a DLL

SHELL32.DLL — “OpenAs_RunDLL”

C:\Windows\System32\rundll32.exe C:\Windows\System32\shell32.dll,OpenAs_RunDLL <file_path>

SHELL32.DLL — “Control_RunDLL”, “Control_RunDLLAsUser” and Control Panel Applets

Image for post
Image for post
Image for post
Image for post
C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,Control_RunDLL C:\WINDOWS\System32\timedate.cpl

Control Panel Items (.CPL)

Image for post
Image for post
C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,Control_RunDLL C:\WINDOWS\System32\main.cpl,@0,1

DEVCLNT.DLL — “DavSetCookie” (Web Dav Client)

C:\WINDOWS\System32\rundll32.exe C:\Windows\system32\davclnt.dll,DavSetCookie <Host> <Share>
C:\Windows\system32\svchost.exe -k LocalService -p -s WebClient

RUNDLL32.EXE — “-sta” / “-localserver” Flags

rundll32.exe –localserver <CLSID_GUID>
rundll32.exe –sta <CLSID_GUID>

RUNDLL32.EXE — Executing HTML / JAVASCRIPT

rundll32.exe javascript:"\..\mshtml,RunHTMLApplication <HTML Code>

Written by

#ThreatHunting #WindowsInternals #Malware #DFIR and occasionally #Python.

Get the Medium app

A button that says 'Download on the App Store', and if clicked it will lead you to the iOS App store
A button that says 'Get it on, Google Play', and if clicked it will lead you to the Google Play store