Potential DCOM InternetExplorer.Application DLL Hijack - Image Load
Last updated on:
Applies to: Log360Log360 Cloud
In this page
About the rule
Rule Type
Standard
Rule Description
Detects potential DLL hijack of "iertutil.dll" found in the DCOM InternetExplorer.Application Class
Severity
Critical
Rule Requirement
Criteria
Action1:
actionname = "Image Loaded" AND PROCESSNAME endswith "\Internet Explorer\iexplore.exe" AND OBJECTNAME endswith "\Internet Explorer\iertutil.dll"
select Action1.HOSTNAME,Action1.MESSAGE,Action1.PROCESSNAME,Action1.PRODUCT_NAME,Action1.OBJECTNAME,Action1.SIGNATURE,Action1.SIGNATURESTATUS
Detection
Execution Mode
realtime
Log Sources
Windows
Author
Roberto Rodriguez @Cyb3rWard0g, Open Threat Research (OTR), wagga


