title: Malware Shellcode in Verclsid Target Process id: b7967e22-3d7e-409b-9ed5-cdae3f9243a1 status: test description: Detects a process access to verclsid.exe that injects shellcode from a Microsoft Office application / VBA macro references: - https://twitter.com/JohnLaTwC/status/837743453039534080 author: John Lambert (tech), Florian Roth (Nextron Systems) date: 2017-03-04 modified: 2021-11-27 tags: - attack.privilege-escalation - attack.stealth - attack.t1055 - detection.emerging-threats logsource: category: process_access product: windows definition: 'Requirements: The following config is required to generate the necessary Event ID 10 Process Access events: VBE7.DLLUNKNOWN' detection: selection_target: TargetImage|endswith: '\verclsid.exe' GrantedAccess: '0x1FFFFF' selection_calltrace_1: CallTrace|contains|all: - '|UNKNOWN(' - 'VBE7.DLL' selection_calltrace_2: SourceImage|contains: '\Microsoft Office\' CallTrace|contains: '|UNKNOWN' condition: selection_target and 1 of selection_calltrace_* falsepositives: - Unknown level: high