Rundll32 Registered COM Objects

 Original Source: [Sigma source]
Title: Rundll32 Registered COM Objects
Status: test
Description:load malicious registered COM objects
References:
  -https://nasbench.medium.com/a-deep-dive-into-rundll32-exe-642344b41e90
  -https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1546.015/T1546.015.md
Author: frack113
Date: 2022-02-13
modified:2023-02-09
Tags:
  • -'attack.privilege-escalation'
  • -'attack.persistence'
  • -'attack.t1546.015'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
Image|endswith:'\rundll32.exe' OriginalFileName:'RUNDLL32.EXE'   selection_cli:
    CommandLine|contains:
      -'-sta '
      -'-localserver '

    CommandLine|contains|all:
      -'{'
      -'}'

  condition:all of selection_*
Falsepositives:
  -Legitimate use
Level: high