Potentially Suspicious Child Process Of Regsvr32

 Original Source: [Sigma source]
Title: Potentially Suspicious Child Process Of Regsvr32
Status: test
Description:Detects potentially suspicious child processes of "regsvr32.exe".
References:
  -https://redcanary.com/blog/intelligence-insights-april-2022/
  -https://www.echotrail.io/insights/search/regsvr32.exe
  -https://www.ired.team/offensive-security/code-execution/t1117-regsvr32-aka-squiblydoo
Author: elhoim, Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)
Date: 2022-05-05
modified:2023-05-26
Tags:
  • -'attack.stealth'
  • -'attack.t1218.010'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    ParentImage|endswith: '\regsvr32.exe'
    Image|endswith:
      -'\calc.exe'
      -'\cscript.exe'
      -'\explorer.exe'
      -'\mshta.exe'
      -'\net.exe'
      -'\net1.exe'
      -'\nltest.exe'
      -'\notepad.exe'
      -'\powershell.exe'
      -'\pwsh.exe'
      -'\reg.exe'
      -'\schtasks.exe'
      -'\werfault.exe'
      -'\wscript.exe'

  filter_main_werfault:
    Image|endswith: '\werfault.exe'
    CommandLine|contains: ' -u -p '
  condition:selection and not 1 of filter_main_*
Falsepositives:
  -Unlikely, but can rarely occur. Apply additional filters accordingly.
Level: high