Ie4uinit Lolbin Use From Invalid Path

 Original Source: [Sigma source]
Title: Ie4uinit Lolbin Use From Invalid Path
Status: test
Description:Detect use of ie4uinit.exe to execute commands from a specially prepared ie4uinit.inf file from a directory other than the usual directories
References:
  -https://lolbas-project.github.io/lolbas/Binaries/Ie4uinit/
  -https://bohops.com/2018/03/10/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence-part-2/
Author: frack113
Date: 2022-05-07
modified:2022-05-16
Tags:
  • -'attack.stealth'
  • -'attack.t1218'
Logsource:
  • product: windows
  • category: process_creation
Detection:
  lolbin:
Image|endswith:'\ie4uinit.exe' OriginalFileName:'IE4UINIT.EXE'   filter_correct:
    CurrentDirectory:
      -'c:\windows\system32\'
      -'c:\windows\sysWOW64\'

  filter_missing:
    CurrentDirectory: 'None'
  condition:lolbin and not 1 of filter_*
Falsepositives:
  -ViberPC updater calls this binary with the following commandline "ie4uinit.exe -ClearIconCache"
Level: medium