title: TAIDOOR RAT DLL Load author: Florian Roth date: 2020/07/30 description: Detects specific process characteristics of Chinese TAIDOOR RAT malware load detection: SELECTION_1: EventID: 1 SELECTION_2: CommandLine: - '*dll,MyStart*' - '*dll MyStart*' SELECTION_3: EventID: 1 SELECTION_4: CommandLine: - '* MyStart' SELECTION_5: CommandLine: - '*rundll32.exe*' condition: (SELECTION_1 and (SELECTION_2 or (SELECTION_3 and SELECTION_4 and SELECTION_5))) falsepositives: - Unknown id: d1aa3382-abab-446f-96ea-4de52908210b level: critical logsource: category: process_creation product: windows references: - https://us-cert.cisa.gov/ncas/analysis-reports/ar20-216a status: experimental tags: - attack.execution - attack.t1055 - attack.t1055.001 ruletype: SIGMA