This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Regsvr32 Execution From Potential Suspicious Location
Original Source:
[Sigma source]
Title:
Regsvr32 Execution From Potential Suspicious Location
Status:
test
Description:
Detects execution of regsvr32 where the DLL is located in a potentially suspicious location.
References:
-https://web.archive.org/web/20171001085340/https://subt0x10.blogspot.com/2017/04/bypass-application-whitelisting-script.html
-https://app.any.run/tasks/34221348-072d-4b70-93f3-aa71f6ebecad/
Author:
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)
Date:
2023-05-26
modified:
None
Tags:
-'attack.stealth'
-'attack.t1218.010'
Logsource:
category: process_creation
product: windows
Detection:
selection_img:
Image|endswith
:
'\regsvr32.exe'
OriginalFileName
:
'REGSVR32.EXE'
selection_cli:
CommandLine|contains
:
-':\ProgramData\'
-':\Temp\'
-':\Users\Public\'
-':\Windows\Temp\'
-'\AppData\Local\Temp\'
-'\AppData\Roaming\'
condition
:
all of selection_*
Falsepositives:
-Some installers might execute "regsvr32" with DLLs located in %TEMP% or in %PROGRAMDATA%. Apply additional filters if necessary.
Level:
medium