BIOC Medium

Rundll32.exe was used to run JavaScript

Attackers may execute malicious JavaScript code (either remotely or locally) using rundll32.exe.

Module:
Platform Analytics
Agent event type:
Process execution
Category:
Execution
Status:
Enabled
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: System Script Proxy Execution (T1216)
Indicator:

Process action type = execution AND target process cmd = * javascript:* AND target process name = rundll32.exe

Preventable: yes