mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-07 09:48:58 +00:00
Remove commas
This commit is contained in:
parent
8d94e993ab
commit
1695bc56dc
@ -19,25 +19,25 @@ logsource:
|
||||
detection:
|
||||
selection:
|
||||
CommandLine|contains:
|
||||
- 'url.dll,*OpenURL'
|
||||
- 'url.dll,*OpenURLA'
|
||||
- 'url.dll,*FileProtocolHandler'
|
||||
- 'zipfldr.dll,*RouteTheCall'
|
||||
- 'shell32.dll,*Control_RunDLL'
|
||||
- 'shell32.dll,*ShellExec_RunDLL'
|
||||
- 'url.dll*OpenURL'
|
||||
- 'url.dll*OpenURLA'
|
||||
- 'url.dll*FileProtocolHandler'
|
||||
- 'zipfldr.dll*RouteTheCall'
|
||||
- 'shell32.dll*Control_RunDLL'
|
||||
- 'shell32.dll*ShellExec_RunDLL'
|
||||
- 'javascript:'
|
||||
- '.RegisterXLL'
|
||||
- 'mshtml.dll,*PrintHTML'
|
||||
- 'advpack.dll,*LaunchINFSection'
|
||||
- 'advpack.dll,*RegisterOCX'
|
||||
- 'ieadvpack.dll,*LaunchINFSection'
|
||||
- 'ieadvpack.dll,*RegisterOCX'
|
||||
- 'ieframe.dll,*OpenURL'
|
||||
- 'shdocvw.dll,*OpenURL'
|
||||
- 'syssetup.dll,*SetupInfObjectInstallAction'
|
||||
- 'setupapi.dll,*InstallHinfSection'
|
||||
- 'pcwutl.dll,*LaunchApplication'
|
||||
- 'dfshim.dll,*ShOpenVerbApplication'
|
||||
- 'mshtml.dll*PrintHTML'
|
||||
- 'advpack.dll*LaunchINFSection'
|
||||
- 'advpack.dll*RegisterOCX'
|
||||
- 'ieadvpack.dll*LaunchINFSection'
|
||||
- 'ieadvpack.dll*RegisterOCX'
|
||||
- 'ieframe.dll*OpenURL'
|
||||
- 'shdocvw.dll*OpenURL'
|
||||
- 'syssetup.dll*SetupInfObjectInstallAction'
|
||||
- 'setupapi.dll*InstallHinfSection'
|
||||
- 'pcwutl.dll*LaunchApplication'
|
||||
- 'dfshim.dll*ShOpenVerbApplication'
|
||||
condition: selection
|
||||
falsepositives:
|
||||
- False positives depend on scripts and administrative tools used in the monitored environment
|
||||
|
Loading…
Reference in New Issue
Block a user