title: EvilNum Golden Chickens Deployment via OCX Files author: Florian Roth date: 2020/07/10 description: Detects Golden Chickens deployment method as used by Evilnum in report published in July 2020 detection: SELECTION_1: EventID: 1 SELECTION_2: CommandLine: '*regsvr32*' SELECTION_3: CommandLine: '*/s*' SELECTION_4: CommandLine: '*/i*' SELECTION_5: CommandLine: '*\AppData\Roaming\\*' SELECTION_6: CommandLine: '*.ocx*' condition: (SELECTION_1 and SELECTION_2 and SELECTION_3 and SELECTION_4 and SELECTION_5 and SELECTION_6) falsepositives: - Unknown id: 8acf3cfa-1e8c-4099-83de-a0c4038e18f0 level: critical logsource: category: process_creation product: windows modified: 2020/08/27 references: - https://www.welivesecurity.com/2020/07/09/more-evil-deep-look-evilnum-toolset/ - https://app.any.run/tasks/33d37fdf-158d-4930-aa68-813e1d5eb8ba/ status: experimental tags: - attack.defense_evasion - attack.t1085 - attack.t1218.011 ruletype: SIGMA