logo

Abusing DLLs EntryPoint for the Fun, (Fri, Dec 12th)

ID: 0fd693da-2de7-51ca-99cc-46153452e608

STIX ID: report--0fd693da-2de7-51ca-99cc-46153452e608

Feed Name: SANS ISC Diary

Date Published: 2025-12-12

Date Updated: 2026-04-19

...
...

The report explains how attackers can embed malicious logic in a Windows DLL’s DllMain entry point so code runs automatically when the DLL is loaded, demonstrating this with a PoC that spawns calc.exe. It notes the use of regsvr32.exe and rundll32.exe as common execution vectors (MITRE ATT&CK T1218.010/.011) and urges analysts to inspect DLL entry points, not just exported functions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.