RegAsm.exe

by Microsoft
Development ToolLOLBinhigh risk

Summary

.NET Assembly Registration Utility. Registers .NET COM-callable assemblies in the Windows registry. Abused as a LOLBin to execute arbitrary code via custom registration functions in .NET DLLs.

RegAsm.exe is the 1996th most commonly executed Windows program in EchoTrail's dataset, observed 311 times across enterprise environments. It typically runs from C:\Windows\Microsoft.NET\Framework64\v4.0.30319 and it is most often launched by msiexec.exe.

1996th
most commonly executed Windows program
311
observed executions
low
statistical confidence

Behavior

Top Paths

  • C:\Windows\Microsoft.NET\Framework64\v4.0.3031986.5%
  • C:\ProgramData\...5.79%
  • C:\Windows\Microsoft.NET\Framework64\v2.0.507273.86%
  • C:\Windows\Microsoft.NET\Framework\v4.0.303192.57%
  • C:\Users\...0.64%
  • C:\Windows\Microsoft.NET\Framework\v2.0.507270.64%

Top Hashes (SHA256)

  • 00271881346e8c7fcf324686631894b977cf0f43a26a2fed8554b9b604a0bd5d26.94%
  • 1136010a4706295f80343fe364d90d5789288dead5ab0ed0e0981d29ad669bbc14.44%
  • de6213ea0a5b21e97dcc862b8545f33784259746ab1797e7805b092861a60d187.5%
  • 1e9516da2ded24d635f5fab0347d34ceb76e50b2a015ebb1ee3b8ee69de5faae5.42%
  • 008407b2ae592dd1e3e2dcc1709bb743dd42415155aca155a94e2da090778f875.14%
  • c5e6e5e81118950386193e8a544a40c0ef9b64a557e55640a0e7494e547240005.14%
  • dc45704ba97d974d157c1c4a27dba402afa595eac2468d8def2ee8d0a2ee9a815.14%
  • 1fa317b9977f8ce780c1bb39567347d233f87646997f55fd6de16c306fbd44e13.75%
  • 17d7cdfd341268f548c9cff3761209bd8b9f2c74993a77e8148a0f058b57dd912.92%
  • 19c4a41aad4928ff060b869758ac00125e37eafdb6085a34c2d5b25b9d19842b2.36%

Process Ancestry

Top Grandparents

Top Parents

Top Children

Rare or environment-specific process names are omitted from ancestry tables. Percentages are of all observed relationships.

Security Analysis

What does RegAsm.exe normally do?

Runs from .NET Framework directory. Used during software installation to register .NET assemblies for COM interop. Short-lived. Uncommon in most environments.

When is RegAsm.exe suspicious?

Loading DLLs from temp directories, user profile paths, or network shares. Spawning child processes (cmd.exe, powershell.exe). Network connections. Execution outside of software installation context.

How do attackers abuse RegAsm.exe?

regasm.exe executes code in .NET assemblies through COM registration entry points (RegisterClass/UnregisterClass). 1. CUSTOM REGISTRATION FUNCTION: Attackers compile a DLL with [ComRegisterFunction] or [ComUnregisterFunction] attributes containing malicious code. Running "regasm.exe /U malicious.dll" executes the code. 2. APPLICATION WHITELISTING BYPASS: Signed Microsoft binary allowed by default policies. 3. PROXY EXECUTION: The malicious code runs in regasm.exe process context, potentially evading detections focused on direct script execution.

Detection guidance

HIGH-CONFIDENCE DETECTIONS: - regasm.exe loading DLLs from %TEMP%, %APPDATA%, Downloads, or network paths - regasm.exe spawning child processes or making network connections - regasm.exe run outside of software installation context DATA SOURCES: Process creation (Sysmon 1), module load (Sysmon 7)

False positive notes

Legitimate during .NET COM interop assembly registration, typically during software installation. Some enterprise applications register COM components at install time.

MITRE ATT&CK techniques

References

Related Processes

Ask Rocky about RegAsm.exe

Rocky answers questions about RegAsm.exe grounded in this same dataset — free, no account needed.

Need this data programmatically? The Rocky API includes 500 free lookups a month. Or just ask Rocky.

Data from EchoTrail's dataset of ~346M Windows process executions. Last extracted 2026-08-04.