This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Regsvr32 DLL Execution With Suspicious File Extension
Original Source:
[Sigma source]
Title:
Regsvr32 DLL Execution With Suspicious File Extension
Status:
test
Description:
Detects the execution of REGSVR32.exe with DLL files masquerading as other files
References:
-https://thedfirreport.com/2021/11/29/continuing-the-bazar-ransomware-story/
-https://blog.talosintelligence.com/2021/10/threat-hunting-in-large-datasets-by.html
-https://guides.lib.umich.edu/c.php?g=282942&p=1885348
-https://harfanglab.io/insidethelab/uac-0057-pressure-ukraine-poland/
Author:
Florian Roth (Nextron Systems), frack113
Date:
2021-11-29
modified:
2025-08-27
Tags:
-'attack.stealth'
-'attack.t1218.010'
Logsource:
category: process_creation
product: windows
Detection:
selection_img:
Image|endswith
:
'\regsvr32.exe'
OriginalFileName
:
'REGSVR32.EXE'
selection_cli:
CommandLine|endswith
:
-'.bin'
-'.bmp'
-'.cr2'
-'.dat'
-'.eps'
-'.gif'
-'.ico'
-'.jpeg'
-'.jpg'
-'.log'
-'.nef'
-'.orf'
-'.png'
-'.raw'
-'.rtf'
-'.sr2'
-'.temp'
-'.tif'
-'.tiff'
-'.tmp'
-'.txt'
condition
:
all of selection_*
Falsepositives:
-Unlikely
Level:
high