Potential Obfuscated Ordinal Call Via Rundll32

Rule Info

Tags
attack.defense_evasion DEMO
Name
Potential Obfuscated Ordinal Call Via Rundll32
Id
43fa5350-db63-4b8f-9a01-789a427074e1
Date
2023-05-17 00:00:00
Modified
None
Description
Detects execution of "rundll32" with potential obfuscated ordinal calls
Reference
Internal Research
Author
Nasreddine Bencherchali (Nextron Systems)
Type
Community Rule

Rule History

Title
Author
Commit
Date
feat: multiple updates and new rules (#4242)
Nasreddine Bencherchali
2023-05-17