Shdocvw.dll

Shell Doc Object and Control Library.

Paths

  • c:\windows\system32\shdocvw.dll
  • c:\windows\syswow64\shdocvw.dll

Commands

Execute

Launch an executable payload via proxy through a URL (information) file by calling OpenURL.

Use case: Load an executable payload by calling a .url file with or without quotes. The .url file extension can be renamed.

Privileges: User

rundll32.exe shdocvw.dll,OpenURL {PATH_ABSOLUTE:.url}

Detection

Resources