Windows Process Creation: Potential Dridex-Related Execution via svchost/regsvr32 and Recon Tools

Alerts on suspicious svchost.exe or regsvr32.exe process executions with matching command-line and parent/child patterns indicative of Dridex activity.

FreeReviewedSigma · Critical · v5
Product
windows
Category
process_creation
Author
Florian Roth (Nextron Systems), oscd.community, Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2019-01-10
Updated
2026-07-31
title: "Windows Process Creation: Potential Dridex-Related Execution via svchost/regsvr32 and Recon Tools"
id: 9bceff19-51a0-4ff4-a496-b3c200ec67e5
status: stable
description: This rule flags Windows process creation patterns consistent with Dridex-like activity, focusing on execution chains involving svchost.exe or regsvr32.exe. It matches svchost.exe launching with user Desktop/AppData artifacts, or regsvr32.exe spawned by excel.exe with specific flags and temporary payload paths, and also looks for an unusual svchost.exe parent spawning whoami.exe and net/net1.exe with discovery-oriented arguments. The detection relies on process creation telemetry including Image, CommandLine, and ParentImage to correlate suspicious parent-child relationships and command-line indicators.
references:
  - https://app.any.run/tasks/993daa5e-112a-4ff6-8b5a-edbcec7c7ba3
  - https://redcanary.com/threat-detection-report/threats/dridex/
  - https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2019/Malware/Dridex/proc_creation_win_malware_dridex.yml
author: Florian Roth (Nextron Systems), oscd.community, Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2019-01-10
modified: 2023-02-03
tags:
  - attack.privilege-escalation
  - attack.stealth
  - attack.t1055
  - attack.discovery
  - attack.t1135
  - attack.t1033
  - detection.emerging-threats
logsource:
  category: process_creation
  product: windows
detection:
  selection_svchost:
    Image|endswith: \svchost.exe
    CommandLine|contains|all:
      - C:\Users\
      - \Desktop\
  filter_svchost:
    ParentImage|startswith: C:\Windows\System32\
  selection_regsvr:
    ParentImage|endswith: \excel.exe
    Image|endswith: \regsvr32.exe
    CommandLine|contains:
      - " -s "
      - \AppData\Local\Temp\
  filter_regsvr:
    CommandLine|contains: .dll
  selection_anomaly_parent:
    ParentImage|endswith: \svchost.exe
  selection_anomaly_child_1:
    Image|endswith: \whoami.exe
    CommandLine|contains: " /all"
  selection_anomaly_child_2:
    Image|endswith:
      - \net.exe
      - \net1.exe
    CommandLine|contains: " view"
  condition: (selection_svchost and not filter_svchost) or (selection_regsvr and not filter_regsvr) or (selection_anomaly_parent and 1 of selection_anomaly_child_*)
falsepositives:
  - Unlikely
level: critical
license: DRL-1.1
related:
  - id: e6eb5a96-9e6f-4a18-9cdd-642cfda21c8e
    type: derived