[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fKCLlfMoHjmSbpAzWgSJ2c-lfW61Zvh1sYT7kque1sOE":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":35,"aiModel":40,"aiConfidence":40,"updatedAt":52,"createdAt":52,"_status":51},652,"What types of files can be executed via rundll32's ShellExecute call?","Beyond `.exe` files, `ShellExecute` supports scripts such as `.js`, `.hta`, and `.url` files. For instance, `rundll32.exe url.dll,OpenURL C:\\4\\calc.hta` launches an HTA that runs `calc.exe`. This expands the attack surface for fileless or script-based attacks, as noted in the [analysis](\u002Fnews\u002Fanalysis-of-executing-programs-using-rundll32).","\u003Cp>Beyond `.exe` files, `ShellExecute` supports scripts such as `.js`, `.hta`, and `.url` files. For instance, `rundll32.exe url.dll,OpenURL C:\\4\\calc.hta` launches an HTA that runs `calc.exe`. This expands the attack surface for fileless or script-based attacks, as noted in the [analysis](\u002Fnews\u002Fanalysis-of-executing-programs-using-rundll32).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fanalysis-of-executing-programs-using-rundll32\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-types-of-files-can-be-executed-via-rundll32s-shellexecute-call-1777482672517","ShellExecute, HTA, JS, URL files, fileless execution",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":33,"readingTime":34,"status":35,"publishedAt":36,"seo":37,"tags":42,"qaPairs":43,"meta":48,"updatedAt":49,"createdAt":50,"_status":51},162,"Analysis of Executing Programs Using rundll32","analysis-of-executing-programs-using-rundll32","Learn how rundll32 uses DLLs like url.dll to execute programs via OpenURL and ShellExecute. Includes batch scanning for exploitable DLLs and PowerShell scripts.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Recently, I came across an interesting article titled 'Abusing Exported Functions and Exposed DCOM Interfaces for Pass-Thru Command Execution and Lateral Movement', which introduced a method of using rundll32.exe to load url.dll and execute programs via the exported function OpenURL. I conducted research on this topic and compiled it into an article to address the following issues:\u003C\u002Fp>\u003Cul>\u003Cli>Details and principles of executing programs using rundll32\u003C\u002Fli>\u003Cli>Using scripts to batch scan DLLs and find DLLs capable of executing programs\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Usage of rundll32 loading DLLs\u003C\u002Fli>\u003Cli>Usage of OpenURL\u003C\u002Fli>\u003Cli>Usage of the API ShellExecute\u003C\u002Fli>\u003Cli>Combining the three to achieve direct program execution via rundll32\u003C\u002Fli>\u003Cli>Finding other available exported functions\u003C\u002Fli>\u003Cli>Using PowerShell scripts to batch obtain DLL exported functions and filter specific DLLs\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Related Details\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Usage of rundll32 loading dll\u003C\u002Fh3>\u003Cp>Official documentation:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fsupport.microsoft.com\u002Fsk-sk\u002Fhelp\u002F164787\u002Finfo-windows-rundll-and-rundll32-interface\u003C\u002Fp>\u003Cp>Usage:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>rundll32 \u003Cdllname>,\u003Centrypoint> \u003Coptional arguments=\"\">\u003C\u002Foptional>\u003C\u002Fentrypoint>\u003C\u002Fdllname>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The parameter \u003Centrypoint> represents the exported function name passed to the dll, defined in the dll as follows:\u003C\u002Fentrypoint>\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>void CALLBACK EntryPoint(HWND hwnd, HINSTANCE hinst, LPSTR lpszCmdLine, int nCmdShow);\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The parameter \u003Coptional arguments=\"\"> corresponds to the LPSTR lpszCmdLine in the dll's exported function\u003C\u002Foptional>\u003C\u002Fp>\u003Cp>This means that through rundll32, the LPSTR lpszCmdLine parameter of the dll's exported function can be controlled\u003C\u002Fp>\u003Ch3>2. Usage of OpenURL\u003C\u002Fh3>\u003Cp>Here, directly refer to the hints in the article, find url.dll, which contains the exported function OpenURL\u003C\u002Fp>\u003Cp>Use IDA to view the exported function OpenURL in url.dll, which calls the API ShellExecute, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017281924_0_c6b71af5ca.jpeg\">\u003C\u002Fp>\u003Cp>View the pseudocode, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017310096_1_31b4fbaf52.jpeg\">\u003C\u002Fp>\u003Cp>Note that the second parameter of ShellExecute is NULL, and the third parameter lpFile corresponds to the passed parameter lpFile\u003C\u002Fp>\u003Ch3>3. Usage of the API ShellExecute\u003C\u002Fh3>\u003Cp>The function prototype and parameter definitions are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>HINSTANCE ShellExecute(\u003Cbr>  _In_opt_ HWND    hwnd,\u003Cbr>  _In_opt_ LPCTSTR lpOperation,\u003Cbr>  _In_     LPCTSTR lpFile,\u003Cbr>  _In_opt_ LPCTSTR lpParameters,\u003Cbr>  _In_opt_ LPCTSTR lpDirectory,\u003Cbr>  _In_     INT     nShowCmd\u003Cbr>);\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>When the second parameter is NULL, it indicates the default operation \"open\"\u003C\u002Fp>\u003Cp>The third parameter lpFile represents the program or file path to be opened\u003C\u002Fp>\u003Cp>That is to say, the parameter lpFile of the exported function OpenURL in url.dll determines the program or file path that API ShellExecute will open.\u003C\u002Fp>\u003Cp>In summary,\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>rundll32.exe url.dll,OpenURL calc.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The actual operation is ShellExecuteA(hwnd, NULL, \"calc.exe\", NULL, NULL, nShowCmd);, which executes the calculator.\u003C\u002Fp>\u003Cp>Using Immunity Debugger for dynamic debugging, trace to ShellExecuteA, verify the judgment, the passed parameter is calc.exe, as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017340962_2_3dea90093f.jpeg\">\u003C\u002Fp>\u003Ch2>0x03 Extended Exploitation\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Find other exploitable exported functions in url.dll\u003C\u002Fh3>\u003Cp>Load url.dll in IDA, select Search - text..., search for ShellExecuteA\u003C\u002Fp>\u003Cp>The exported function FileProtocolHandler also calls API ShellExecute, as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017385317_3_ee45b67fa4.jpeg\">\u003C\u002Fp>\u003Cp>The test command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>rundll32.exe url.dll,FileProtocolHandler calc.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Execute the calculator.\u003C\u002Fp>\u003Ch3>2. Check if other DLLs contain the export function OpenURL\u003C\u002Fh3>\u003Cp>\u003Cstrong>Implementation approach:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Enumerate the export functions of all DLLs under %windir%\u002Fsystem32, and filter out DLLs that contain the export function OpenURL\u003C\u002Fp>\u003Cp>To obtain DLL export functions via PowerShell, refer to FuzzySecurity's code at the following address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FFuzzySecurity\u002FPowerShell-Suite\u002Fblob\u002Fmaster\u002FGet-Exports.ps1\u003C\u002Fp>\u003Cp>Based on this code, add functionality to enumerate DLLs, retrieve their export functions separately, and perform the judgment\u003C\u002Fp>\u003Cp>\u003Cstrong>Implementation details:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>(1) Enumerate all DLLs under c:\\windows\\system32:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$DllSearchPath = dir c:\\windows\\system32\\*.dll\u003Cbr>\u003Cbr>foreach($DllName in $DllSearchPath)\u003Cbr>{   \u003Cbr>\t$DllName.Name\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(2) For c:\\windows\\system32\\auditpolmsg.dll\u003C\u002Fp>\u003Cp>An error will be reported indicating incorrect input string format, so add try-catch judgment to the statement $OffsetPtr = New-Object System.Intptr -ArgumentList $($HModule.ToInt64() + $ExportRVA)\u003C\u002Fp>\u003Cp>Code location:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FFuzzySecurity\u002FPowerShell-Suite\u002Fblob\u002Fmaster\u002FGet-Exports.ps1#L141\u003C\u002Fp>\u003Cp>(3) For c:\\windows\\system32\\avicap.dll\u003C\u002Fp>\u003Cp>An error occurs: Attempted to read or write protected memory. For the statement $EXPORT_DIRECTORY_FLAGS = [system.runtime.interopservices.marshal]::PtrToStructure($OffsetPtr, [type]$IMAGE_EXPORT_DIRECTORY)\u003C\u002Fp>\u003Cp>Add try-catch handling\u003C\u002Fp>\u003Cp>(4) The current code only supports 32-bit DLL detection\u003C\u002Fp>\u003Cp>Complete code can be referenced at:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fraw.githubusercontent.某开源项目.ps1\u003C\u002Fp>\u003Cp>Execution as shown below, obtaining the other two DLLs: ieframe.dll and shdocvw.dll\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017409340_4_1750fdcd09.jpeg\">\u003C\u002Fp>\u003Cp>Load ieframe.dll with IDA, view the export function OpenURL, pseudocode as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017456776_5_fa2ebe1836.jpeg\">\u003C\u002Fp>\u003Cp>From CInternetShortcut, it can be inferred that the executed file is a .url file\u003C\u002Fp>\u003Cp>Create a .url file with the following content:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>[InternetShortcut]\u003Cbr>URL=c:\\windows\\system32\\calc.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>cmd:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>rundll32.exe ieframe.dll,OpenURL C:\\4\\calc.url\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Successfully executed, calculator popped up\u003C\u002Fp>\u003Cp>Similarly, shdocvw.dll yields the same test result\u003C\u002Fp>\u003Ch3>3. Types of executed programs\u003C\u002Fh3>\u003Cp>Calling API ShellExecute to execute programs supports not only exe but also scripts\u003C\u002Fp>\u003Cp>For example, executing a js file with the following content:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>WScript.Echo(\"1\");\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>cmd:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>rundll32.exe url.dll,OpenURL C:\\4\\echo.js\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Dialog box popped up after execution\u003C\u002Fp>\u003Cp>For example, an hta file with the following content:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp> \u003Cbr>\u003Cmeta http-equiv=\"Content-Type\" content=\"text\u002Fhtml; charset=utf-8\">\u003Cbr> \u003Cbr>\u003Cscript language=\"VBScript\">\u003Cbr>Window.ReSizeTo 0, 0\u003Cbr>Window.moveTo -2000, -2000\u003Cbr>Set objShell = CreateObject(\"Wscript.Shell\")\u003Cbr>objShell.Run \"calc.exe\"\u003Cbr>self.close\u003Cbr>\u003C\u002Fscript>\u003Cbr>\u003Cbr>demo\u003Cbr>\u003Cbr> \u003Cbr> \u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>cmd:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>rundll32.exe url.dll,OpenURLA C:\\4\\calc.hta\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Calculator pops up after execution\u003C\u002Fp>\u003Cp>For example, a URL file with the following content:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>[InternetShortcut]\u003Cbr>URL=c:\\windows\\system32\\calc.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>cmd:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>rundll32.exe ieframe.dll,OpenURL C:\\4\\calc.url\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Successfully executed, calculator pops up\u003C\u002Fp>\u003Ch3>4. More exploitation methods\u003C\u002Fh3>\u003Cp>Hexacorn shared another usable DLL and export function in his article:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>rundll32 zipfldr.dll, RouteTheCall calc.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Of course, there are more DLLs available for use, which will not be introduced in this article for now\u003C\u002Fp>\u003Ch2>0x04 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article analyzes the details of using rundll32.exe to load url.dll and execute programs through the export function OpenURL, extends it, attempts to use scripts to batch scan DLLs under %windir%\u002Fsystem32, finds DLLs capable of executing programs, and verifies the conclusions of bohops and Hexacorn respectively.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Recently, I came across an interesting article titled 'Abusing Exported Functions and Exposed DCOM Interfaces for Pass-Thru Command Execution and Lateral Movement', which introduced a method of using rundll32.exe to load url.dll and execute programs via the exported function OpenURL. I conducted research on this topic and compiled it into an article to address the following issues:\u003C\u002Fp>\u003Cul>\u003Cli>Details and principles of executing programs using rundll32\u003C\u002Fli>\u003Cli>Using scripts to batch scan DLLs and find DLLs capable of executing programs\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Usage of rundll32 loading DLLs\u003C\u002Fli>\u003Cli>Usage of OpenURL\u003C\u002Fli>\u003Cli>Usage of the API ShellExecute\u003C\u002Fli>\u003Cli>Combining the three to achieve direct program execution via rundll32\u003C\u002Fli>\u003Cli>Finding other available exported functions\u003C\u002Fli>\u003Cli>Using PowerShell scripts to batch obtain DLL exported functions and filter specific DLLs\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Related Details\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Usage of rundll32 loading dll\u003C\u002Fh3>\u003Cp>Official documentation:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fsupport.microsoft.com\u002Fsk-sk\u002Fhelp\u002F164787\u002Finfo-windows-rundll-and-rundll32-interface\u003C\u002Fp>\u003Cp>Usage:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>rundll32 \u003Cdllname>,\u003Centrypoint> \u003Coptional arguments=\"\">\u003C\u002Foptional>\u003C\u002Fentrypoint>\u003C\u002Fdllname>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The parameter \u003Centrypoint> represents the exported function name passed to the dll, defined in the dll as follows:\u003C\u002Fentrypoint>\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>void CALLBACK EntryPoint(HWND hwnd, HINSTANCE hinst, LPSTR lpszCmdLine, int nCmdShow);\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The parameter \u003Coptional arguments=\"\"> corresponds to the LPSTR lpszCmdLine in the dll's exported function\u003C\u002Foptional>\u003C\u002Fp>\u003Cp>This means that through rundll32, the LPSTR lpszCmdLine parameter of the dll's exported function can be controlled\u003C\u002Fp>\u003Ch3>2. Usage of OpenURL\u003C\u002Fh3>\u003Cp>Here, directly refer to the hints in the article, find url.dll, which contains the exported function OpenURL\u003C\u002Fp>\u003Cp>Use IDA to view the exported function OpenURL in url.dll, which calls the API ShellExecute, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017281924_0_c6b71af5ca-1.jpeg\">\u003C\u002Fp>\u003Cp>View the pseudocode, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017310096_1_31b4fbaf52-1.jpeg\">\u003C\u002Fp>\u003Cp>Note that the second parameter of ShellExecute is NULL, and the third parameter lpFile corresponds to the passed parameter lpFile\u003C\u002Fp>\u003Ch3>3. Usage of the API ShellExecute\u003C\u002Fh3>\u003Cp>The function prototype and parameter definitions are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>HINSTANCE ShellExecute(\u003Cbr>  _In_opt_ HWND    hwnd,\u003Cbr>  _In_opt_ LPCTSTR lpOperation,\u003Cbr>  _In_     LPCTSTR lpFile,\u003Cbr>  _In_opt_ LPCTSTR lpParameters,\u003Cbr>  _In_opt_ LPCTSTR lpDirectory,\u003Cbr>  _In_     INT     nShowCmd\u003Cbr>);\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>When the second parameter is NULL, it indicates the default operation \"open\"\u003C\u002Fp>\u003Cp>The third parameter lpFile represents the program or file path to be opened\u003C\u002Fp>\u003Cp>That is to say, the parameter lpFile of the exported function OpenURL in url.dll determines the program or file path that API ShellExecute will open.\u003C\u002Fp>\u003Cp>In summary,\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>rundll32.exe url.dll,OpenURL calc.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The actual operation is ShellExecuteA(hwnd, NULL, \"calc.exe\", NULL, NULL, nShowCmd);, which executes the calculator.\u003C\u002Fp>\u003Cp>Using Immunity Debugger for dynamic debugging, trace to ShellExecuteA, verify the judgment, the passed parameter is calc.exe, as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017340962_2_3dea90093f-1.jpeg\">\u003C\u002Fp>\u003Ch2>0x03 Extended Exploitation\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Find other exploitable exported functions in url.dll\u003C\u002Fh3>\u003Cp>Load url.dll in IDA, select Search - text..., search for ShellExecuteA\u003C\u002Fp>\u003Cp>The exported function FileProtocolHandler also calls API ShellExecute, as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017385317_3_ee45b67fa4-1.jpeg\">\u003C\u002Fp>\u003Cp>The test command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>rundll32.exe url.dll,FileProtocolHandler calc.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Execute the calculator.\u003C\u002Fp>\u003Ch3>2. Check if other DLLs contain the export function OpenURL\u003C\u002Fh3>\u003Cp>\u003Cstrong>Implementation approach:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Enumerate the export functions of all DLLs under %windir%\u002Fsystem32, and filter out DLLs that contain the export function OpenURL\u003C\u002Fp>\u003Cp>To obtain DLL export functions via PowerShell, refer to FuzzySecurity's code at the following address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FFuzzySecurity\u002FPowerShell-Suite\u002Fblob\u002Fmaster\u002FGet-Exports.ps1\u003C\u002Fp>\u003Cp>Based on this code, add functionality to enumerate DLLs, retrieve their export functions separately, and perform the judgment\u003C\u002Fp>\u003Cp>\u003Cstrong>Implementation details:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>(1) Enumerate all DLLs under c:\\windows\\system32:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$DllSearchPath = dir c:\\windows\\system32\\*.dll\u003Cbr>\u003Cbr>foreach($DllName in $DllSearchPath)\u003Cbr>{   \u003Cbr>\t$DllName.Name\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(2) For c:\\windows\\system32\\auditpolmsg.dll\u003C\u002Fp>\u003Cp>An error will be reported indicating incorrect input string format, so add try-catch judgment to the statement $OffsetPtr = New-Object System.Intptr -ArgumentList $($HModule.ToInt64() + $ExportRVA)\u003C\u002Fp>\u003Cp>Code location:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FFuzzySecurity\u002FPowerShell-Suite\u002Fblob\u002Fmaster\u002FGet-Exports.ps1#L141\u003C\u002Fp>\u003Cp>(3) For c:\\windows\\system32\\avicap.dll\u003C\u002Fp>\u003Cp>An error occurs: Attempted to read or write protected memory. For the statement $EXPORT_DIRECTORY_FLAGS = [system.runtime.interopservices.marshal]::PtrToStructure($OffsetPtr, [type]$IMAGE_EXPORT_DIRECTORY)\u003C\u002Fp>\u003Cp>Add try-catch handling\u003C\u002Fp>\u003Cp>(4) The current code only supports 32-bit DLL detection\u003C\u002Fp>\u003Cp>Complete code can be referenced at:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fraw.githubusercontent.某开源项目.ps1\u003C\u002Fp>\u003Cp>Execution as shown below, obtaining the other two DLLs: ieframe.dll and shdocvw.dll\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017409340_4_1750fdcd09-1.jpeg\">\u003C\u002Fp>\u003Cp>Load ieframe.dll with IDA, view the export function OpenURL, pseudocode as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017456776_5_fa2ebe1836-1.jpeg\">\u003C\u002Fp>\u003Cp>From CInternetShortcut, it can be inferred that the executed file is a .url file\u003C\u002Fp>\u003Cp>Create a .url file with the following content:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>[InternetShortcut]\u003Cbr>URL=c:\\windows\\system32\\calc.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>cmd:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>rundll32.exe ieframe.dll,OpenURL C:\\4\\calc.url\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Successfully executed, calculator popped up\u003C\u002Fp>\u003Cp>Similarly, shdocvw.dll yields the same test result\u003C\u002Fp>\u003Ch3>3. Types of executed programs\u003C\u002Fh3>\u003Cp>Calling API ShellExecute to execute programs supports not only exe but also scripts\u003C\u002Fp>\u003Cp>For example, executing a js file with the following content:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>WScript.Echo(\"1\");\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>cmd:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>rundll32.exe url.dll,OpenURL C:\\4\\echo.js\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Dialog box popped up after execution\u003C\u002Fp>\u003Cp>For example, an hta file with the following content:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp> \u003Cbr>\u003Cmeta http-equiv=\"Content-Type\" content=\"text\u002Fhtml; charset=utf-8\">\u003Cbr> \u003Cbr>\u003Cscript language=\"VBScript\">\u003Cbr>Window.ReSizeTo 0, 0\u003Cbr>Window.moveTo -2000, -2000\u003Cbr>Set objShell = CreateObject(\"Wscript.Shell\")\u003Cbr>objShell.Run \"calc.exe\"\u003Cbr>self.close\u003Cbr>\u003C\u002Fscript>\u003Cbr>\u003Cbr>demo\u003Cbr>\u003Cbr> \u003Cbr> \u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>cmd:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>rundll32.exe url.dll,OpenURLA C:\\4\\calc.hta\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Calculator pops up after execution\u003C\u002Fp>\u003Cp>For example, a URL file with the following content:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>[InternetShortcut]\u003Cbr>URL=c:\\windows\\system32\\calc.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>cmd:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>rundll32.exe ieframe.dll,OpenURL C:\\4\\calc.url\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Successfully executed, calculator pops up\u003C\u002Fp>\u003Ch3>4. More exploitation methods\u003C\u002Fh3>\u003Cp>Hexacorn shared another usable DLL and export function in his article:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>rundll32 zipfldr.dll, RouteTheCall calc.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Of course, there are more DLLs available for use, which will not be introduced in this article for now\u003C\u002Fp>\u003Ch2>0x04 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article analyzes the details of using rundll32.exe to load url.dll and execute programs through the export function OpenURL, extends it, attempts to use scripts to batch scan DLLs under %windir%\u002Fsystem32, finds DLLs capable of executing programs, and verifies the conclusions of bohops and Hexacorn respectively.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",842,"Onedaysec",3,4,"published","2026-02-02T07:38:21.454Z",{"title":38,"description":14,"keywords":39,"ogImage":40,"canonicalUrl":40,"noIndex":41},"Exploiting rundll32 for Program Execution: DLL Analysis & Techniques","rundll32, DLL exploitation, OpenURL, ShellExecute, PowerShell scanning, lateral movement, program execution, exported functions, url.dll, security research",null,false,[],{"docs":44,"hasNextPage":41},[45,4,46,47],653,651,650,{"title":40,"description":40,"image":40},"2026-07-24T15:37:12.084Z","2026-07-23T16:01:54.366Z","draft","2026-07-23T16:13:59.935Z"]