Regsvr32 DLL Execution With Uncommon Extension (50919691-7302-437f-8e10-1fe088afa145)
Detects a "regsvr32" execution where the DLL doesn't contain a common file extension.
Cluster A | Galaxy A | Cluster B | Galaxy B | Level |
---|---|---|---|---|
Regsvr32 DLL Execution With Uncommon Extension (50919691-7302-437f-8e10-1fe088afa145) | Sigma-Rules | Hijack Execution Flow - T1574 (aedfca76-3b30-4866-b2aa-0f1d7fd1e4b6) | Attack Pattern | 1 |