DCOM InternetExplorer.Application Iertutil DLL Hijack - Security

 Original Source: [Sigma source]
Title: DCOM InternetExplorer.Application Iertutil DLL Hijack - Security
Status: test
Description:Detects a threat actor creating a file named `iertutil.dll` in the `C:\Program Files\Internet Explorer\` directory over the network for a DCOM InternetExplorer DLL Hijack scenario.
References:
  -https://threathunterplaybook.com/hunts/windows/201009-RemoteDCOMIErtUtilDLLHijack/notebook.html
Author: Roberto Rodriguez @Cyb3rWard0g, Open Threat Research (OTR)
Date: 2020-10-12
modified:2022-11-26
Tags:
  • -'attack.lateral-movement'
  • -'attack.t1021.002'
  • -'attack.t1021.003'
Logsource:
  • product: windows
  • service: security
Detection:
  selection:
    EventID: '5145'
    RelativeTargetName|endswith: '\Internet Explorer\iertutil.dll'
  filter:
    SubjectUserName|endswith: '$'
  condition:selection and not filter
Falsepositives:
  -Unknown
Level: high