Regsvr32 Execution From Potential Suspicious Location

 Original Source: [Sigma source]
Title: Regsvr32 Execution From Potential Suspicious Location
Status: test
Description:Detects execution of regsvr32 where the DLL is located in a potentially suspicious location.
References:
  -https://web.archive.org/web/20171001085340/https://subt0x10.blogspot.com/2017/04/bypass-application-whitelisting-script.html
  -https://app.any.run/tasks/34221348-072d-4b70-93f3-aa71f6ebecad/
Author: Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)
Date: 2023-05-26
modified:None
Tags:
  • -'attack.stealth'
  • -'attack.t1218.010'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
Image|endswith:'\regsvr32.exe' OriginalFileName:'REGSVR32.EXE'   selection_cli:
    CommandLine|contains:
      -':\ProgramData\'
      -':\Temp\'
      -':\Users\Public\'
      -':\Windows\Temp\'
      -'\AppData\Local\Temp\'
      -'\AppData\Roaming\'

  condition:all of selection_*
Falsepositives:
  -Some installers might execute "regsvr32" with DLLs located in %TEMP% or in %PROGRAMDATA%. Apply additional filters if necessary.
Level: medium