Suspicious Regsvr32 Execution From Remote Share

 Original Source: [Sigma source]
Title: Suspicious Regsvr32 Execution From Remote Share
Status: test
Description:Detects REGSVR32.exe to execute DLL hosted on remote shares
References:
  -https://thedfirreport.com/2022/10/31/follina-exploit-leads-to-domain-compromise/
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2022-10-31
modified:None
Tags:
  • -'attack.stealth'
  • -'attack.t1218.010'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
Image|endswith:'\regsvr32.exe' OriginalFileName:'\REGSVR32.EXE'   selection_cli:
    CommandLine|contains: ' \\\\'
  condition:all of selection_*
Falsepositives:
  -Unknown
Level: high