Dllhost.EXE Execution Anomaly

 Original Source: [Sigma source]
Title: Dllhost.EXE Execution Anomaly
Status: test
Description:Detects a "dllhost" process spawning with no commandline arguments which is very rare to happen and could indicate process injection activity or malware mimicking similar system processes.
References:
  -https://redcanary.com/blog/child-processes/
  -https://nasbench.medium.com/what-is-the-dllhost-exe-process-actually-running-ef9fe4c19c08
  -https://www.ncsc.gov.uk/static-assets/documents/malware-analysis-reports/goofy-guineapig/NCSC-MAR-Goofy-Guineapig.pdf
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2022-06-27
modified:2023-05-15
Tags:
  • -'attack.privilege-escalation'
  • -'attack.stealth'
  • -'attack.t1055'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    Image|endswith: '\dllhost.exe'
    CommandLine:
      -'dllhost.exe'
      -'dllhost'

  filter_main_null:
    CommandLine: 'None'
  condition:selection and not 1 of filter_main_*
Falsepositives:
  -Unlikely
Level: high