Unsigned DLL Loaded by Windows Utility

 Original Source: [Sigma source]
Title: Unsigned DLL Loaded by Windows Utility
Status: test
Description:Detects windows utilities loading an unsigned or untrusted DLL. Adversaries often abuse those programs to proxy execution of malicious code.
References:
  -https://www.elastic.co/security-labs/Hunting-for-Suspicious-Windows-Libraries-for-Execution-and-Evasion
  -https://akhere.hashnode.dev/hunting-unsigned-dlls-using-kql
  -https://unit42.paloaltonetworks.com/unsigned-dlls/?web_view=true
Author: Swachchhanda Shrawan Poudel
Date: 2024-02-28
modified:2025-10-07
Tags:
  • -'attack.stealth'
  • -'attack.t1218.011'
  • -'attack.t1218.010'
Logsource:
  • product: windows
  • category: image_load
Detection:
  selection:
    Image|endswith:
      -'\InstallUtil.exe'
      -'\RegAsm.exe'
      -'\RegSvcs.exe'
      -'\regsvr32.exe'
      -'\rundll32.exe'

  filter_main_signed:
    Signed: 'true'
  filter_main_sig_status:
    SignatureStatus:
      -'errorChaining'
      -'errorCode_endpoint'
      -'errorExpired'
      -'trusted'
      -'Valid'

  filter_main_signed_null:
    Signed: 'None'
  filter_main_signed_empty:
    Signed:
      -''
      -'-'

  filter_main_sig_status_null:
    SignatureStatus: 'None'
  filter_main_sig_status_empty:
    SignatureStatus:
      -''
      -'-'

  filter_main_windows_installer:
    Image:
      -'C:\Windows\SysWOW64\rundll32.exe'
      -'C:\Windows\System32\rundll32.exe'

    ImageLoaded|startswith: 'C:\Windows\Installer\'
    ImageLoaded|endswith:
      -'.tmp-\Microsoft.Deployment.WindowsInstaller.dll'
      -'.tmp-\Avira.OE.Setup.CustomActions.dll'

  filter_main_assembly:
    Image|startswith:
      -'C:\Windows\SysWOW64\'
      -'C:\Windows\System32\'
      -'C:\Windows\Microsoft.NET\Framework64'

    Image|endswith: '\RegAsm.exe'
    ImageLoaded|endswith: '.dll'
    ImageLoaded|startswith: 'C:\Windows\assembly\NativeImages'
  filter_optional_klite_codec:
    Image:
      -'C:\Windows\SysWOW64\regsvr32.exe'
      -'C:\Windows\System32\regsvr32.exe'

    ImageLoaded|startswith:
      -'C:\Program Files (x86)\K-Lite Codec Pack\'
      -'C:\Program Files\K-Lite Codec Pack\'

  condition:selection and not 1 of filter_main_* and not 1 of filter_optional_*
Falsepositives:
  -Unknown
Level: medium