Suspicious Advpack Call Via Rundll32.EXE

Rule Info

Tags
attack.defense_evasion DEMO
Name
Suspicious Advpack Call Via Rundll32.EXE
Id
a1473adb-5338-4a20-b4c3-126763e2d3d3
Date
2023-05-17 00:00:00
Modified
None
Description
Detects execution of "rundll32" calling "advpack.dll" with potential obfuscated ordinal calls in order to leverage the "RegisterOCX" function
Author
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)
Type
Community Rule

Rule History

Title
Author
Commit
Date
feat: multiple updates and new rules (#4242)
Nasreddine Bencherchali
2023-05-17