Suspicious Wscript Spawning Rundll32 to Load Remote DLL (via process_creation)

PremiumReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-05-26
Updated
2026-08-28

ATT&CK techniques

Execution → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule detects wscript.exe launching rundll32.exe, an unusual parent-child relationship used by the Strela Stealer JavaScript loader to execute a WebDAV-hosted DLL payload. Legitimate scripts rarely invoke rundll32 in this manner.

Related detections9 linkedT1059.007 — drag to rearrange
Windows Process Creation: Suspicious Children Spawned by HTML Help (hh.exe)
Windows: Alert on Suspicious HH.EXE Process Execution
Possible React2Shell CVE-2025-55182 Prototype Pollution Exploitation
Suspicious Node.js Script Execution from AppData Roaming
Possible Reflected XSS via cPanel cpanelwebcall Endpoint CVE-2023-29489
Malicious Rundll32 Loading an Export From a User Path (via process_creation)
SocGholish Fake Browser Update Script Execution (via process_creation)
Renamed Regsvr32 or Rundll32 Loading a DLL With a Non-Standard Extension (via process_creation)
Malicious Rundll32 DllRegisterServer Execution From a User-Writable Path (via process_creation)
Suspicious Wscript Spawning Rundll32 to Load Remote DLL (via process_creation)
Pivot detection · T1059.007 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.