Dllhost.EXE Initiated Network Connection To Non-Local IP Address
Description
Detects Dllhost.EXE initiating a network connection to a non-local IP address. Aside from Microsoft own IP range that needs to be excluded. Network communication from Dllhost will depend entirely on the hosted DLL. An initial baseline is recommended before deployment.
Query · sigma
selection: Image|endswith: \dllhost.exe Initiated: 'true' filter_main_local_ranges: DestinationIp|cidr: - ::1/128 - 10.0.0.0/8 - 127.0.0.0/8 - 172.16.0.0/12 - 192.168.0.0/16 - 169.254.0.0/16 - fc00::/7 - fe80::/10 filter_main_msrange: DestinationIp|cidr: - 20.184.0.0/13 - 20.192.0.0/10 - 23.72.0.0/13 - 51.10.0.0/15 - 51.103.0.0/16 - 51.104.0.0/15 - 52.224.0.0/11 - 150.171.0.0/19 - 204.79.197.0/24 condition: selection and not 1 of filter_main_*
Known false positives
- Communication to other corporate systems that use IP addresses from public address spaces