Potentially Suspicious Regsvr32 HTTP IP Pattern

 Original Source: [Sigma source]
Title: Potentially Suspicious Regsvr32 HTTP IP Pattern
Status: test
Description:Detects regsvr32 execution to download and install DLLs located remotely where the address is an IP address.
References:
  -https://twitter.com/mrd0x/status/1461041276514623491
  -https://twitter.com/tccontre18/status/1480950986650832903
  -https://lolbas-project.github.io/lolbas/Binaries/Regsvr32/
Author: Florian Roth (Nextron Systems)
Date: 2022-01-11
modified:2023-05-24
Tags:
  • -'attack.stealth'
  • -'attack.t1218.010'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
Image|endswith:'\regsvr32.exe' OriginalFileName:'REGSVR32.EXE'   selection_ip:
    CommandLine|contains:
      -' /i:http://1'
      -' /i:http://2'
      -' /i:http://3'
      -' /i:http://4'
      -' /i:http://5'
      -' /i:http://6'
      -' /i:http://7'
      -' /i:http://8'
      -' /i:http://9'
      -' /i:https://1'
      -' /i:https://2'
      -' /i:https://3'
      -' /i:https://4'
      -' /i:https://5'
      -' /i:https://6'
      -' /i:https://7'
      -' /i:https://8'
      -' /i:https://9'
      -' -i:http://1'
      -' -i:http://2'
      -' -i:http://3'
      -' -i:http://4'
      -' -i:http://5'
      -' -i:http://6'
      -' -i:http://7'
      -' -i:http://8'
      -' -i:http://9'
      -' -i:https://1'
      -' -i:https://2'
      -' -i:https://3'
      -' -i:https://4'
      -' -i:https://5'
      -' -i:https://6'
      -' -i:https://7'
      -' -i:https://8'
      -' -i:https://9'

  condition:all of selection_*
Falsepositives:
  -FQDNs that start with a number such as "7-Zip"
Level: high