Injected Browser Process Spawning Rundll32 - GuLoader Activity
Description
Detects the execution of installed GuLoader malware on the host. GuLoader is initiating network connections via the rundll32.exe process that is spawned via a browser parent(injected) process.
Query · sigma
selection: ParentImage|endswith: - \chrome.exe - \firefox.exe - \msedge.exe Image|endswith: \rundll32.exe CommandLine|endswith: \rundll32.exe condition: selection
Known false positives
- Unlikely