T1218.011 Rundll32 in real malware
ATT&CK technique T1218.011 Rundll32 appears in 4 publicly analyzed samples on MalwareAnalyzer by Cyble, 0.0% of the analyzed corpus. Seven-day prevalence is flat (0 recent vs 0 prior). Most associated families: Cerbu.
Tactics: stealth
Prevalence in the corpus
- Samples exhibiting T1218.011: 4
- Share of analyzed corpus: 0.0%
- Last 7 days: 0 · prior 7 days: 0 (flat)
Malware families using T1218.011
- Cerbu - 1 sample
Example samples
- db1a47f9f9efc539f618c41ba949f05176f83a09043f94d6ac4cf9b5bd672c7a - malicious
- ffa24be3e2cc8d7ac27bdce483537b73fdeef57e429883e91aef1589a812669b - malicious
- a9af701a7a57022dcc0b2148a39c08fe45e9b030428652dc6250a8b6e5e00d53 - malicious
- libwinpthread-1.dll - malicious
Canonical technique definition: MITRE ATT&CK T1218.011 (ATT&CK v19.1, CC BY 4.0).
Frequently asked about T1218.011
- How common is ATT&CK T1218.011 (Rundll32) in real malware?
- ATT&CK technique T1218.011 Rundll32 appears in 4 publicly analyzed samples on MalwareAnalyzer by Cyble, 0.0% of the analyzed corpus. Seven-day prevalence is flat (0 recent vs 0 prior). Most associated families: Cerbu.
- Which malware families use T1218.011?
- In this corpus T1218.011 is most associated with Cerbu (1). Counts are analyzed samples per family in which the technique was observed.
- What share of analyzed samples use T1218.011?
- 0.0% of the publicly analyzed corpus (4 of 114575 samples) exhibits T1218.011. Technique attribution comes from behavior captured during real sandbox detonation and from static analysis, not from a vendor label.
All ATT&CK techniques in the corpus · Latest analyzed threats