Suspicious Renamed Comsvcs DLL Loaded By Rundll32

 Original Source: [Sigma source]
Title: Suspicious Renamed Comsvcs DLL Loaded By Rundll32
Status: test
Description:Detects rundll32 loading a renamed comsvcs.dll to dump process memory
References:
  -https://twitter.com/sbousseaden/status/1555200155351228419
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2022-08-14
modified:2023-02-17
Tags:
  • -'attack.credential-access'
  • -'attack.t1003.001'
Logsource:
  • product: windows
  • category: image_load
Detection:
  selection:
    Image|endswith: '\rundll32.exe'
    Hashes|contains:
      -'IMPHASH=eed93054cb555f3de70eaa9787f32ebb'
      -'IMPHASH=5e0dbdec1fce52daae251a110b4f309d'
      -'IMPHASH=eadbccbb324829acb5f2bbe87e5549a8'
      -'IMPHASH=407ca0f7b523319d758a40d7c0193699'
      -'IMPHASH=281d618f4e6271e527e6386ea6f748de'

  filter:
    ImageLoaded|endswith: '\comsvcs.dll'
  condition:selection and not filter
Falsepositives:
  -Unlikely
Level: high