Potential Edputil.DLL Sideloading

 Original Source: [Sigma source]
Title: Potential Edputil.DLL Sideloading
Status: test
Description:Detects potential DLL sideloading of "edputil.dll"
References:
  -https://alternativeto.net/news/2023/5/cybercriminals-use-wordpad-vulnerability-to-spread-qbot-malware/
Author: X__Junior (Nextron Systems)
Date: 2023-06-09
modified:None
Tags:
  • -'attack.persistence'
  • -'attack.privilege-escalation'
  • -'attack.execution'
  • -'attack.stealth'
  • -'attack.t1574.001'
Logsource:
  • category: image_load
  • product: windows
Detection:
  selection:
    ImageLoaded|endswith: '\edputil.dll'
  filter_main_generic:
    ImageLoaded|startswith:
      -'C:\Windows\System32\'
      -'C:\Windows\SysWOW64\'
      -'C\Windows\WinSxS\'

  condition:selection and not 1 of filter_main_*
Falsepositives:
  -Unlikely
Level: high