Sagan critical stable other
[WINDOWS-SYSMON] Reverse rundll command
[WINDOWS-SYSMON] Reverse rundll command
Detection Logic
alert any $HOME_NET any -> $HOME_NET any (msg:"[WINDOWS-SYSMON] Reverse rundll command"; program:*Sysmon*
| *Security*; event_id:1,4688; content:"WScript.exe"; nocase; content:" lldnur "; nocase; reference:url,thedfirreport.com/2023/01/09/unwrapping-ursnifs-gifts/; classtype:trojan-activity; sid:5013840; rev:1; metadata:deployment Endpoint,affected_product NONE,affected_version NONE,mitigation NONE,deprecation_reason NONE,tag NONE, created_at 2023_02_01, updated_at 2023_02_01, mitre_tactic_id TA0005, mitre_technique_id T1027;) Field Validations
Loading…
Comments (0)
Loading comments...