Potential DCOM InternetExplorer.Application DLL Hijack

 Original Source: [Sigma source]
Title: Potential DCOM InternetExplorer.Application DLL Hijack
Status: test
Description:Detects potential DLL hijack of "iertutil.dll" found in the DCOM InternetExplorer.Application Class over the network
References:
  -https://threathunterplaybook.com/hunts/windows/201009-RemoteDCOMIErtUtilDLLHijack/notebook.html
Author: Roberto Rodriguez @Cyb3rWard0g, Open Threat Research (OTR), wagga
Date: 2020-10-12
modified:2022-12-18
Tags:
  • -'attack.lateral-movement'
  • -'attack.t1021.002'
  • -'attack.t1021.003'
Logsource:
  • product: windows
  • category: file_event
Detection:
  selection:
    Image: 'System'
    TargetFilename|endswith: '\Internet Explorer\iertutil.dll'
  condition:selection
Falsepositives:
  -Unknown
Level: critical