Analytics BIOC
Low
✕
Rundll32.exe executes a rare unsigned module
Rundll32.exe executes a rare unsigned module, which can indicate an attacker's malicious execution.
- Module:
- Platform Analytics
- Data source:
- XDR Agent
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: System Binary Proxy Execution: Rundll32 (T1218.011)
Detector tags: LOLBIN Execution Analytics
Attacker's goals:
Evading detections by running code from a signed Microsoft executable.
Investigative actions:
Check whether the loaded module with the corresponding hash is benign and if this was a desired behavior as part of its normal execution flow.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
2 variations:
- Rundll32.exe executes a rare unsigned module with very high entropy Medium (parent: Low)
- Rundll32.exe executes a rare unsigned module with suspicious characteristics Medium (parent: Low)