BIOC Informational

Rundll32 loads a known abused DLL

Rundll32.exe is called to execute an arbitrary binary, this execution may also bypass whitelisting defenses as a signed Microsoft application.

Module:
Platform Analytics
Agent event type:
Process execution
Category:
Execution
Status:
Enabled
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: System Binary Proxy Execution: Rundll32 (T1218.011)
Indicator:

Process action type = execution AND target process cmd != *control_rundll*cscui.dll* AND *control_rundll*srchadmin.dll* AND *control_rundll*keymgr.dll* AND *control_rundll*input.dll* AND *fileprotocolhandler*.zip* AND *fileprotocolhandler*.htm* AND *fileprotocolhandler*.png* AND *fileprotocolhandler*.pdf* AND *fileprotocolhandler*.dbk* AND target process cmd = *advpack.dll*registerocx*.dll* , *advpack.dll*registerocx*.exe* , *ieadvpack.dll*launchinfsection*.inf* , *ieframe.dll*openurl*.url* , *Mshtml.dll*printhtml*.hta* , *pcwutl.dll*launchapplication*.exe* , *setupapi.dll*installhinfsection*defaultInstall*.inf* , *shdocvw.dll*openurl*.url , *shell32.dll*control_rundll*.dll* , *shell32.dll*shellexec_rundll*.exe* , *syssetup.dll*setupinfobjectinstallaction*.inf* , *url.dll*openurl*.hta* , *url.dll*openurl*.url* , *url.dll*openurl*file* , *url.dll*fileprotocolhandler*.hta* , *url.dll*fileprotocolhandler*.url* , *url.dll*fileprotocolhandler*file:* , *zipfldr.dll*routethecall*.exe* , *zipfldr.dll*routethecall*file:* AND target process name = rundll32.exe Process initiated by != ie4uinit.exe AND msdt.exe AND bomgar-scc.exe AND control.exe AND cgo name != ie4uinit.exe AND msdt.exe AND bomgar-scc.exe AND control.exe AND os parent name != ie4uinit.exe AND msdt.exe AND bomgar-scc.exe AND control.exe

Preventable: yes