Malware Shellcode in Verclsid Target Process — Detection Rule

Detects a process access to verclsid.exe that injects shellcode from a Microsoft Office application / VBA macro

Read the full analysis on IntelFusions