Suspicious Rundll32 Invoking Inline VBScript

 Original Source: [Sigma source]
Title: Suspicious Rundll32 Invoking Inline VBScript
Status: test
Description:Detects suspicious process related to rundll32 based on command line that invokes inline VBScript as seen being used by UNC2452
References:
  -https://www.microsoft.com/security/blog/2021/03/04/goldmax-goldfinder-sibot-analyzing-nobelium-malware/
Author: Florian Roth (Nextron Systems)
Date: 2021-03-05
modified:2022-10-09
Tags:
  • -'attack.privilege-escalation'
  • -'attack.stealth'
  • -'attack.t1055'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    CommandLine|contains|all:
      -'rundll32.exe'
      -'Execute'
      -'RegRead'
      -'window.close'

  condition:selection
Falsepositives:
  -Unknown
Level: high