verclsid.exe

by Microsoft
Operating SystemLOLBinmedium risk

Summary

COM Object Verification utility. Verifies and validates COM class IDs. Can be abused to execute code by registering malicious COM objects and invoking their verification.

verclsid.exe is the 1551st most commonly executed Windows program in EchoTrail's dataset, observed 632 times across enterprise environments. It typically runs from C:\Windows\System32 and it is most often launched by RuntimeBroker.exe.

1551st
most commonly executed Windows program
632
observed executions
low
statistical confidence

Behavior

Top Paths

  • C:\Windows\System3299.53%
  • C:\Windows\SysWOW640.47%

Top Hashes (SHA256)

  • 3ee33c6afffccb94dc642943ec071cd062bf0b4f5cc5474c4250149e08e06bd334.06%
  • 69da38c640682d46377fe8a6cb304da97893ab8d4989e5fa54edfd397a50c00b16.44%
  • ac6e1f614cb902c0abe4297646e21c70590624b652a080bfbb8407b1ab52609d14.6%
  • bd061706d94afd7a809f0ea613a236c9ecae8488c39446d0843284ae4a2c602712.42%
  • 8614efbf351984bb416f5ce7825d1aeedfa368110c551810fbe33941b6ec9b4610.07%
  • 18c4e76431643aaf2113a5c4556cbe1d79cbc8113e4b0904a6205d73a89260455.54%
  • 4dfee721ff49f16696ce2c9a4ba066c4c7acafd8d3ce7609e417b0a0cfeaa72e2.01%
  • c70e4ded6a371904dff62cc9ef4bd3c723c41dd615083da811940386d08d55381.68%
  • 9c95ef6902dcd9b9c825a44142d3e7e6af3f265fc76da38726dee98b0c7e11271.17%
  • cc6a47869fdba5ec67a20e0714b9b3162881462e36457c08b1b13b84683889e00.67%

Process Ancestry

Top Grandparents

Top Parents

Rare or environment-specific process names are omitted from ancestry tables. Percentages are of all observed relationships.

Security Analysis

What does verclsid.exe normally do?

Runs from C:\Windows\System32. Called by Explorer to verify COM objects before loading them (e.g., shell extensions, thumbnail providers). Short-lived verification process.

When is verclsid.exe suspicious?

verclsid.exe loading unusual DLLs. Spawning child processes. Network connections. Invoked with CLSID parameters pointing to non-standard COM objects.

How do attackers abuse verclsid.exe?

PROXY EXECUTION: Attackers register a malicious COM object (DLL) and use verclsid.exe to load and execute it. verclsid.exe is a signed Microsoft binary, so the DLL executes in a trusted process context. Can bypass application whitelisting that allows verclsid.exe but blocks direct DLL execution.

Detection guidance

MEDIUM-CONFIDENCE: - verclsid.exe loading DLLs from non-standard paths - verclsid.exe spawning child processes - verclsid.exe making network connections DATA SOURCES: Process creation (Sysmon 1), module load (Sysmon 7)

False positive notes

Normal Explorer activity — verclsid.exe is called frequently to validate shell extensions and COM objects. The key is unusual DLL paths or child process creation.

MITRE ATT&CK techniques

References

Related Processes

Ask Rocky about verclsid.exe

Rocky answers questions about verclsid.exe grounded in this same dataset — free, no account needed.

Need this data programmatically? The Rocky API includes 500 free lookups a month. Or just ask Rocky.

Data from EchoTrail's dataset of ~346M Windows process executions. Last extracted 2026-08-04.