Regsvr32 Execution From Highly Suspicious Location

 Original Source: [Sigma source]
Title: Regsvr32 Execution From Highly Suspicious Location
Status: test
Description:Detects execution of regsvr32 where the DLL is located in a highly suspicious locations
References:
  -Internal Research
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2023-05-26
modified:None
Tags:
  • -'attack.stealth'
  • -'attack.t1218.010'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
Image|endswith:'\regsvr32.exe' OriginalFileName:'REGSVR32.EXE'   selection_path_1:
    CommandLine|contains:
      -':\PerfLogs\'
      -':\Temp\'
      -'\Windows\Registration\CRMLog'
      -'\Windows\System32\com\dmp\'
      -'\Windows\System32\FxsTmp\'
      -'\Windows\System32\Microsoft\Crypto\RSA\MachineKeys\'
      -'\Windows\System32\spool\drivers\color\'
      -'\Windows\System32\spool\PRINTERS\'
      -'\Windows\System32\spool\SERVERS\'
      -'\Windows\System32\Tasks_Migrated\'
      -'\Windows\System32\Tasks\Microsoft\Windows\SyncCenter\'
      -'\Windows\SysWOW64\com\dmp\'
      -'\Windows\SysWOW64\FxsTmp\'
      -'\Windows\SysWOW64\Tasks\Microsoft\Windows\PLA\System\'
      -'\Windows\SysWOW64\Tasks\Microsoft\Windows\SyncCenter\'
      -'\Windows\Tasks\'
      -'\Windows\Tracing\'

  selection_path_2:
    CommandLine|contains:
      -' "C:\'
      -' C:\'
      -' 'C:\'
      -'D:\'

  selection_exclude_known_dirs:
    CommandLine|contains:
      -'C:\Program Files (x86)\'
      -'C:\Program Files\'
      -'C:\ProgramData\'
      -'C:\Users\'
      -' C:\Windows\'
      -' "C:\Windows\'
      -' 'C:\Windows\'

  filter_main_empty:
    CommandLine: ''
  filter_main_null:
    CommandLine: 'None'
  condition:selection_img and (selection_path_1 or (selection_path_2 and not selection_exclude_known_dirs)) and not 1 of filter_main_*
Falsepositives:
  -Unlikely
Level: high