This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Unsigned DLL Loaded by Windows Utility
Original Source:
[Sigma source]
Title:
Unsigned DLL Loaded by Windows Utility
Status:
test
Description:
Detects windows utilities loading an unsigned or untrusted DLL. Adversaries often abuse those programs to proxy execution of malicious code.
References:
-https://www.elastic.co/security-labs/Hunting-for-Suspicious-Windows-Libraries-for-Execution-and-Evasion
-https://akhere.hashnode.dev/hunting-unsigned-dlls-using-kql
-https://unit42.paloaltonetworks.com/unsigned-dlls/?web_view=true
Author:
Swachchhanda Shrawan Poudel
Date:
2024-02-28
modified:
2025-10-07
Tags:
-'attack.stealth'
-'attack.t1218.011'
-'attack.t1218.010'
Logsource:
product: windows
category: image_load
Detection:
selection:
Image|endswith
:
-'\InstallUtil.exe'
-'\RegAsm.exe'
-'\RegSvcs.exe'
-'\regsvr32.exe'
-'\rundll32.exe'
filter_main_signed:
Signed
:
'true'
filter_main_sig_status:
SignatureStatus
:
-'errorChaining'
-'errorCode_endpoint'
-'errorExpired'
-'trusted'
-'Valid'
filter_main_signed_null:
Signed
:
'None'
filter_main_signed_empty:
Signed
:
-''
-'-'
filter_main_sig_status_null:
SignatureStatus
:
'None'
filter_main_sig_status_empty:
SignatureStatus
:
-''
-'-'
filter_main_windows_installer:
Image
:
-'C:\Windows\SysWOW64\rundll32.exe'
-'C:\Windows\System32\rundll32.exe'
ImageLoaded|startswith
:
'C:\Windows\Installer\'
ImageLoaded|endswith
:
-'.tmp-\Microsoft.Deployment.WindowsInstaller.dll'
-'.tmp-\Avira.OE.Setup.CustomActions.dll'
filter_main_assembly:
Image|startswith
:
-'C:\Windows\SysWOW64\'
-'C:\Windows\System32\'
-'C:\Windows\Microsoft.NET\Framework64'
Image|endswith
:
'\RegAsm.exe'
ImageLoaded|endswith
:
'.dll'
ImageLoaded|startswith
:
'C:\Windows\assembly\NativeImages'
filter_optional_klite_codec:
Image
:
-'C:\Windows\SysWOW64\regsvr32.exe'
-'C:\Windows\System32\regsvr32.exe'
ImageLoaded|startswith
:
-'C:\Program Files (x86)\K-Lite Codec Pack\'
-'C:\Program Files\K-Lite Codec Pack\'
condition
:
selection and not 1 of filter_main_* and not 1 of filter_optional_*
Falsepositives:
-Unknown
Level:
medium