This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Suspicious Renamed Comsvcs DLL Loaded By Rundll32
Original Source:
[Sigma source]
Title:
Suspicious Renamed Comsvcs DLL Loaded By Rundll32
Status:
test
Description:
Detects rundll32 loading a renamed comsvcs.dll to dump process memory
References:
-https://twitter.com/sbousseaden/status/1555200155351228419
Author:
Nasreddine Bencherchali (Nextron Systems)
Date:
2022-08-14
modified:
2023-02-17
Tags:
-'attack.credential-access'
-'attack.t1003.001'
Logsource:
product: windows
category: image_load
Detection:
selection:
Image|endswith
:
'\rundll32.exe'
Hashes|contains
:
-'IMPHASH=eed93054cb555f3de70eaa9787f32ebb'
-'IMPHASH=5e0dbdec1fce52daae251a110b4f309d'
-'IMPHASH=eadbccbb324829acb5f2bbe87e5549a8'
-'IMPHASH=407ca0f7b523319d758a40d7c0193699'
-'IMPHASH=281d618f4e6271e527e6386ea6f748de'
filter:
ImageLoaded|endswith
:
'\comsvcs.dll'
condition
:
selection and not filter
Falsepositives:
-Unlikely
Level:
high