Injected Browser Process Spawning Rundll32 - GuLoader Activity — Detection Rule

Detects the execution of installed GuLoader malware on the host. GuLoader is initiating network connections via the rundll32.exe process that is spawned via a browser parent(injected) process.

Read the full analysis on IntelFusions