Title:
Scripting/CommandLine Process Spawned Regsvr32
Status:
test
Description:Detects various command line and scripting engines/processes such as "PowerShell", "Wscript", "Cmd", etc. spawning a "regsvr32" instance.
References:
-https://web.archive.org/web/20171001085340/https://subt0x10.blogspot.com/2017/04/bypass-application-whitelisting-script.html
-https://app.any.run/tasks/34221348-072d-4b70-93f3-aa71f6ebecad/
Author: Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)
Date: 2023-05-26
modified:None
Tags:
- -'attack.stealth'
- -'attack.t1218.010'
Logsource:
- category: process_creation
- product: windows
Detection:
selection:
ParentImage|endswith:
-'\cmd.exe'
-'\cscript.exe'
-'\mshta.exe'
-'\powershell_ise.exe'
-'\powershell.exe'
-'\pwsh.exe'
-'\wscript.exe'
Image|endswith:
'\regsvr32.exe'
filter_main_rpcproxy:
ParentImage:
'C:\Windows\System32\cmd.exe'
CommandLine|endswith:
' /s C:\Windows\System32\RpcProxy\RpcProxy.dll'
condition:
selection and not 1 of filter_main_*
Falsepositives:
-Legitimate ".bat", ".hta", ".ps1" or ".vbs" scripts leverage legitimately often. Apply additional filter and exclusions as necessary
-Some legitimate Windows services
Level:
medium