Potential Obfuscated Ordinal Call Via Rundll32

 Original Source: [Sigma source]
Title: Potential Obfuscated Ordinal Call Via Rundll32
Status: test
Description:Detects execution of "rundll32" with potential obfuscated ordinal calls
References:
  -Internal Research
  -https://www.youtube.com/watch?v=52tAmVLg1KM&t=2070s
Author: Nasreddine Bencherchali (Nextron Systems), Swachchhanda Shrawan Poudel (Nextron Systems)
Date: 2023-05-17
modified:2025-02-23
Tags:
  • -'attack.stealth'
  • -'attack.t1027.010'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
Image|endswith:'\rundll32.exe' OriginalFileName:'RUNDLL32.EXE' CommandLine|contains:'rundll32'   selection_cli:
    CommandLine|contains:
      -'#+'
      -'#-'
      -'#0'
      -'#655'
      -'#656'

  condition:all of selection_*
Falsepositives:
  -Unknown
Level: medium