Regsvr32 DLL Execution With Suspicious File Extension

 Original Source: [Sigma source]
Title: Regsvr32 DLL Execution With Suspicious File Extension
Status: test
Description:Detects the execution of REGSVR32.exe with DLL files masquerading as other files
References:
  -https://thedfirreport.com/2021/11/29/continuing-the-bazar-ransomware-story/
  -https://blog.talosintelligence.com/2021/10/threat-hunting-in-large-datasets-by.html
  -https://guides.lib.umich.edu/c.php?g=282942&p=1885348
  -https://harfanglab.io/insidethelab/uac-0057-pressure-ukraine-poland/
Author: Florian Roth (Nextron Systems), frack113
Date: 2021-11-29
modified:2025-08-27
Tags:
  • -'attack.stealth'
  • -'attack.t1218.010'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
Image|endswith:'\regsvr32.exe' OriginalFileName:'REGSVR32.EXE'   selection_cli:
    CommandLine|endswith:
      -'.bin'
      -'.bmp'
      -'.cr2'
      -'.dat'
      -'.eps'
      -'.gif'
      -'.ico'
      -'.jpeg'
      -'.jpg'
      -'.log'
      -'.nef'
      -'.orf'
      -'.png'
      -'.raw'
      -'.rtf'
      -'.sr2'
      -'.temp'
      -'.tif'
      -'.tiff'
      -'.tmp'
      -'.txt'

  condition:all of selection_*
Falsepositives:
  -Unlikely
Level: high