Malicious more_eggs LOLBIN Scriptlet Execution via ie4uinit BaseSettings Abuse (via process_creation)

PremiumReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-05-18
Updated
2026-08-28

ATT&CK techniques

Execution → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects the ie4uinit LOLBIN being run with the -basesettings flag from a user-writable location such as AppData, the first-stage technique in the more_eggs TA4557 resume-lure intrusion where a copied ie4uinit loaded a malicious SCT through a planted ieuinit.inf. Adversaries relocate this signed binary to abuse its inf-driven command execution while evading path-based controls, so an out-of-System32 ie4uinit with -basesettings indicates staged code execution.

Related detections9 linkedT1204.002 — drag to rearrange
Suspicious FileFix TypedPaths Entry Containing PowerShell or URL
Suspicious VBA Runtime Loaded by Process from OneNote Exported Directory
Windows: Detect Advanced Installer PSF AI_STUBS Executables with OriginalFileName popupwrapper.exe
Suspicious Cabinet Extraction of Masqueraded vstm Archive via extrac32
Suspicious Interlock Fake Updater Executable Execution
Malicious Office Application Loading a User-Path DLL via Regsvr32 or Rundll32 (via process_creation)
Suspicious Program Execution From a Mounted ISO or Disk Image (via process_creation)
SocGholish Fake Browser Update Script Execution (via process_creation)
Malicious DLL Execution via Wuauclt Update Handler (via process_creation)
Malicious more_eggs LOLBIN Scriptlet Execution via ie4uinit BaseSettings Abuse (via process_creation)
Pivot detection · T1204.002 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.