Process Memory Dump Via Comsvcs.DLL

 Original Source: [Sigma source]
Title: Process Memory Dump Via Comsvcs.DLL
Status: test
Description:Detects a process memory dump via "comsvcs.dll" using rundll32, covering multiple different techniques (ordinal, minidump function, etc.)
References:
  -https://twitter.com/shantanukhande/status/1229348874298388484
  -https://twitter.com/pythonresponder/status/1385064506049630211?s=21
  -https://twitter.com/Hexacorn/status/1224848930795552769
  -https://modexp.wordpress.com/2019/08/30/minidumpwritedump-via-com-services-dll/
  -https://twitter.com/SBousseaden/status/1167417096374050817
  -https://twitter.com/Wietze/status/1542107456507203586
  -https://github.com/Hackndo/lsassy/blob/14d8f8ae596ecf22b449bfe919829173b8a07635/lsassy/dumpmethod/comsvcs.py
  -https://www.youtube.com/watch?v=52tAmVLg1KM&t=2070s
Author: Florian Roth (Nextron Systems), Modexp, Nasreddine Bencherchali (Nextron Systems), Swachchhanda Shrawan Poudel (Nextron Systems)
Date: 2020-02-18
modified:2025-02-23
Tags:
  • -'attack.credential-access'
  • -'attack.stealth'
  • -'attack.t1036'
  • -'attack.t1003.001'
  • -'car.2013-05-009'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
Image|endswith:'\rundll32.exe' OriginalFileName:'RUNDLL32.EXE' CommandLine|contains:'rundll32'   selection_cli_1:
    CommandLine|contains|all:
      -'comsvcs'
      -'full'

    CommandLine|contains:
      -'#-'
      -'#+'
      -'#24'
      -'24 '
      -'MiniDump'
      -'#65560'

  selection_generic:
    CommandLine|contains|all:
      -'24'
      -'comsvcs'
      -'full'

    CommandLine|contains:
      -' #'
      -',#'
      -', #'
      -'"#'

  condition:(selection_img and 1 of selection_cli_*) or selection_generic
Falsepositives:
  -Unlikely
Level: high