Sigma medium test sigma

Unsigned DLL Loaded by Windows Utility

Detects windows utilities loading an unsigned or untrusted DLL. Adversaries often abuse those programs to proxy execution of malicious code.

View Source

Detection Logic

{
  "selection": {
    "Image
| endswith": [
      "\\InstallUtil.exe",
      "\\RegAsm.exe",
      "\\RegSvcs.exe",
      "\\regsvr32.exe",
      "\\rundll32.exe"
    ]
  },
  "filter_main_signed": {
    "Signed": "true"
  },
  "filter_main_sig_status": {
    "SignatureStatus": [
      "errorChaining",
      "errorCode_endpoint",
      "errorExpired",
      "trusted",
      "Valid"
    ]
  },
  "filter_main_signed_null": {
    "Signed": null
  },
  "filter_main_signed_empty": {
    "Signed": [
      "",
      "-"
    ]
  },
  "filter_main_sig_status_null": {
    "SignatureStatus": null
  },
  "filter_main_sig_status_empty": {
    "SignatureStatus": [
      "",
      "-"
    ]
  },
  "filter_main_windows_installer": {
    "Image": [
      "C:\\Windows\\SysWOW64\\rundll32.exe",
      "C:\\Windows\\System32\\rundll32.exe"
    ],
    "ImageLoaded
| startswith": "C:\\Windows\\Installer\\",
    "ImageLoaded
| endswith": [
      ".tmp-\\Microsoft.Deployment.WindowsInstaller.dll",
      ".tmp-\\Avira.OE.Setup.CustomActions.dll"
    ]
  },
  "filter_main_assembly": {
    "Image
| startswith": [
      "C:\\Windows\\SysWOW64\\",
      "C:\\Windows\\System32\\",
      "C:\\Windows\\Microsoft.NET\\Framework64"
    ],
    "Image
| endswith": "\\RegAsm.exe",
    "ImageLoaded
| endswith": ".dll",
    "ImageLoaded
| startswith": "C:\\Windows\\assembly\\NativeImages"
  },
  "filter_optional_klite_codec": {
    "Image": [
      "C:\\Windows\\SysWOW64\\regsvr32.exe",
      "C:\\Windows\\System32\\regsvr32.exe"
    ],
    "ImageLoaded
| startswith": [
      "C:\\Program Files (x86)\\K-Lite Codec Pack\\",
      "C:\\Program Files\\K-Lite Codec Pack\\"
    ]
  },
  "condition": "selection and not 1 of filter_main_* and not 1 of filter_optional_*"
}

False Positives

  • Unknown

Field Validations

Loading…

Comments (0)

Loading comments...