Abusable DLL Potential Sideloading From Suspicious Location

 Original Source: [Sigma source]
Title: Abusable DLL Potential Sideloading From Suspicious Location
Status: test
Description:Detects potential DLL sideloading of DLLs that are known to be abused from suspicious locations
References:
  -https://www.trendmicro.com/en_us/research/23/f/behind-the-scenes-unveiling-the-hidden-workings-of-earth-preta.html
  -https://research.checkpoint.com/2023/beyond-the-horizon-traveling-the-world-on-camaro-dragons-usb-flash-drives/
Author: X__Junior (Nextron Systems)
Date: 2023-07-11
modified:None
Tags:
  • -'attack.execution'
  • -'attack.t1059'
Logsource:
  • category: image_load
  • product: windows
Detection:
  selection_dll:
    ImageLoaded|endswith:
      -'\coreclr.dll'
      -'\facesdk.dll'
      -'\HPCustPartUI.dll'
      -'\libcef.dll'
      -'\ZIPDLL.dll'

  selection_folders_1:
    ImageLoaded|contains:
      -':\Perflogs\'
      -':\Users\Public\'
      -'\Temporary Internet'
      -'\Windows\Temp\'

  selection_folders_2:
    - ImageLoaded|contains|all:
      - ':\Users\'
      - '\Favorites\'
    - ImageLoaded|contains|all:
      - ':\Users\'
      - '\Favourites\'
    - ImageLoaded|contains|all:
      - ':\Users\'
      - '\Contacts\'
    - ImageLoaded|contains|all:
      - ':\Users\'
      - '\Pictures\'
  condition:selection_dll and 1 of selection_folders_*
Falsepositives:
  -Unknown
Level: high