Regsvr32 Execution From Highly Suspicious Location
Description
Detects execution of regsvr32 where the DLL is located in a highly suspicious locations
Query · sigma
selection_img: - Image|endswith: \regsvr32.exe - OriginalFileName: REGSVR32.EXE selection_path_1: CommandLine|contains: - :\PerfLogs\ - :\Temp\ - \Windows\Registration\CRMLog - \Windows\System32\com\dmp\ - \Windows\System32\FxsTmp\ - \Windows\System32\Microsoft\Crypto\RSA\MachineKeys\ - \Windows\System32\spool\drivers\color\ - \Windows\System32\spool\PRINTERS\ - \Windows\System32\spool\SERVERS\ - \Windows\System32\Tasks_Migrated\ - \Windows\System32\Tasks\Microsoft\Windows\SyncCenter\ - \Windows\SysWOW64\com\dmp\ - \Windows\SysWOW64\FxsTmp\ - \Windows\SysWOW64\Tasks\Microsoft\Windows\PLA\System\ - \Windows\SysWOW64\Tasks\Microsoft\Windows\SyncCenter\ - \Windows\Tasks\ - \Windows\Tracing\ selection_path_2: CommandLine|contains: - ' "C:\' - ' C:\' - ' ''C:\' - D:\ selection_exclude_known_dirs: CommandLine|contains: - C:\Program Files (x86)\ - C:\Program Files\ - C:\ProgramData\ - C:\Users\ - ' C:\Windows\' - ' "C:\Windows\' - ' ''C:\Windows\' filter_main_empty: CommandLine: '' filter_main_null: CommandLine: null condition: selection_img and (selection_path_1 or (selection_path_2 and not selection_exclude_known_dirs)) and not 1 of filter_main_*
Known false positives
- Unlikely