Rundll32 loads a known abused DLL
Rundll32.exe is called to execute an arbitrary binary, this execution may also bypass whitelisting defenses as a signed Microsoft application.
- Module:
- Platform Analytics
- Agent event type:
- Process execution
- Category:
- Execution
- Status:
- Enabled
Process action type = execution AND target process cmd != *control_rundll*cscui.dll* AND *control_rundll*srchadmin.dll* AND *control_rundll*keymgr.dll* AND *control_rundll*input.dll* AND *fileprotocolhandler*.zip* AND *fileprotocolhandler*.htm* AND *fileprotocolhandler*.png* AND *fileprotocolhandler*.pdf* AND *fileprotocolhandler*.dbk* AND target process cmd = *advpack.dll*registerocx*.dll* , *advpack.dll*registerocx*.exe* , *ieadvpack.dll*launchinfsection*.inf* , *ieframe.dll*openurl*.url* , *Mshtml.dll*printhtml*.hta* , *pcwutl.dll*launchapplication*.exe* , *setupapi.dll*installhinfsection*defaultInstall*.inf* , *shdocvw.dll*openurl*.url , *shell32.dll*control_rundll*.dll* , *shell32.dll*shellexec_rundll*.exe* , *syssetup.dll*setupinfobjectinstallaction*.inf* , *url.dll*openurl*.hta* , *url.dll*openurl*.url* , *url.dll*openurl*file* , *url.dll*fileprotocolhandler*.hta* , *url.dll*fileprotocolhandler*.url* , *url.dll*fileprotocolhandler*file:* , *zipfldr.dll*routethecall*.exe* , *zipfldr.dll*routethecall*file:* AND target process name = rundll32.exe Process initiated by != ie4uinit.exe AND msdt.exe AND bomgar-scc.exe AND control.exe AND cgo name != ie4uinit.exe AND msdt.exe AND bomgar-scc.exe AND control.exe AND os parent name != ie4uinit.exe AND msdt.exe AND bomgar-scc.exe AND control.exe
Preventable: yes