Title:
Potential 7za.DLL Sideloading
Status:
test
Description:Detects potential DLL sideloading of "7za.dll"
References:
-https://www.gov.pl/attachment/ee91f24d-3e67-436d-aa50-7fa56acf789d
Author: X__Junior
Date: 2023-06-09
modified:None
Tags:
- -'attack.persistence'
- -'attack.privilege-escalation'
- -'attack.execution'
- -'attack.stealth'
- -'attack.t1574.001'
Logsource:
- category: image_load
- product: windows
Detection:
selection:
ImageLoaded|endswith:
'\7za.dll'
filter_main_legit_path:
Image|startswith:
-'C:\Program Files (x86)\'
-'C:\Program Files\'
ImageLoaded|startswith:
-'C:\Program Files (x86)\'
-'C:\Program Files\'
condition:
selection and not 1 of filter_main_*
Falsepositives:
-Legitimate third party application located in "AppData" may leverage this DLL to offer 7z compression functionality and may generate false positives. Apply additional filters as needed.
Level:
low