Windows Suspicious ShellExec_RunDLL via SHELL32.DLL Ordinal in Parent Command Line
Alert on Windows process starts where parent command line invokes SHELL32.DLL ShellExec_RunDLL using a matched ordinal and spawns suspicious binaries.
FreeUnreviewedSigmahighv1
windows-suspicious-shellexec-rundll-via-shell32-dll-ordinal-in-parent-command-li-8823e85d
title: Windows Suspicious ShellExec_RunDLL via SHELL32.DLL Ordinal in Parent Command Line
id: 35bd9b7e-ea3b-4c30-9a3f-f1a700462712
related:
- id: d87bd452-6da1-456e-8155-7dc988157b7d
type: derived
- id: 8823e85d-31d8-473e-b7f4-92da070f0fc6
type: derived
status: test
description: "This rule flags process creation events where the parent command line includes SHELL32.DLL and references the ShellExec_RunDLL export by ordinal (e.g., #568/#570/#572/#576), a stealthier way to invoke DLL functionality. Attackers may use ordinals to evade detections that trigger only on the function name or standard rundll32-style strings. It relies on process creation telemetry, specifically the parent command line contents and the image path of the spawned child process."
references:
- https://redcanary.com/blog/raspberry-robin/
- https://www.microsoft.com/en-us/security/blog/2022/10/27/raspberry-robin-worm-part-of-larger-ecosystem-facilitating-pre-ransomware-activity/
- https://github.com/SigmaHQ/sigma/issues/1009
- https://strontic.github.io/xcyclopedia/library/shell32.dll-65DA072F25DE83D9F83653E3FEA3644D.html
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_rundll32_susp_shellexec_ordinal_execution.yml
author: Swachchhanda Shrawan Poudel, Huntrule Team
date: 2024-12-01
tags:
- attack.stealth
- attack.t1218.011
logsource:
category: process_creation
product: windows
detection:
selection_parent_img:
ParentCommandLine|contains: SHELL32.DLL
selection_parent_ordinal:
ParentCommandLine|contains:
- "#568"
- "#570"
- "#572"
- "#576"
selection_susp_cli_parent:
- ParentCommandLine|contains:
- comspec
- iex
- Invoke-
- msiexec
- odbcconf
- regsvr32
- ParentCommandLine|contains:
- \Desktop\
- \ProgramData\
- \Temp\
- \Users\Public\
selection_susp_child_img:
Image|endswith:
- \bash.exe
- \bitsadmin.exe
- \cmd.exe
- \cscript.exe
- \curl.exe
- \mshta.exe
- \msiexec.exe
- \msxsl.exe
- \odbcconf.exe
- \powershell.exe
- \pwsh.exe
- \regsvr32.exe
- \schtasks.exe
- \wmic.exe
- \wscript.exe
condition: all of selection_parent_* and 1 of selection_susp_*
falsepositives:
- Unknown
level: high
license: DRL-1.1
What it detects
This rule flags process creation events where the parent command line includes SHELL32.DLL and references the ShellExec_RunDLL export by ordinal (e.g., #568/#570/#572/#576), a stealthier way to invoke DLL functionality. Attackers may use ordinals to evade detections that trigger only on the function name or standard rundll32-style strings. It relies on process creation telemetry, specifically the parent command line contents and the image path of the spawned child process.
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.