Potential DCOM InternetExplorer.Application DLL Hijack - Image Load

 Original Source: [Sigma source]
Title: Potential DCOM InternetExplorer.Application DLL Hijack - Image Load
Status: test
Description:Detects potential DLL hijack of "iertutil.dll" found in the DCOM InternetExplorer.Application Class
References:
  -https://threathunterplaybook.com/hunts/windows/201009-RemoteDCOMIErtUtilDLLHijack/notebook.html
Author: Roberto Rodriguez @Cyb3rWard0g, Open Threat Research (OTR), wagga
Date: 2020-10-12
modified:2022-12-18
Tags:
  • -'attack.lateral-movement'
  • -'attack.t1021.002'
  • -'attack.t1021.003'
Logsource:
  • product: windows
  • category: image_load
Detection:
  selection:
    Image|endswith: '\Internet Explorer\iexplore.exe'
    ImageLoaded|endswith: '\Internet Explorer\iertutil.dll'
  condition:selection
Falsepositives:
  -Unknown
Level: critical