Potentially Suspicious Regsvr32 HTTP/FTP Pattern

 Original Source: [Sigma source]
Title: Potentially Suspicious Regsvr32 HTTP/FTP Pattern
Status: test
Description:Detects regsvr32 execution to download/install/register new DLLs that are hosted on Web or FTP servers.
References:
  -https://twitter.com/mrd0x/status/1461041276514623491
  -https://twitter.com/tccontre18/status/1480950986650832903
  -https://lolbas-project.github.io/lolbas/Binaries/Regsvr32/
Author: Florian Roth (Nextron Systems)
Date: 2023-05-24
modified:2023-05-26
Tags:
  • -'attack.stealth'
  • -'attack.t1218.010'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
Image|endswith:'\regsvr32.exe' OriginalFileName:'REGSVR32.EXE'   selection_flag:
    CommandLine|contains:
      -' /i'
      -' -i'

  selection_protocol:
    CommandLine|contains:
      -'ftp'
      -'http'

  condition:all of selection_*
Falsepositives:
  -Unknown
Level: medium