Title:
Potential Goopdate.DLL Sideloading
Status:
test
Description:Detects potential DLL sideloading of "goopdate.dll", a DLL used by googleupdate.exe
References:
-https://www.ncsc.gov.uk/static-assets/documents/malware-analysis-reports/goofy-guineapig/NCSC-MAR-Goofy-Guineapig.pdf
Author: X__Junior (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)
Date: 2023-05-15
modified:2025-10-07
Tags:
- -'attack.persistence'
- -'attack.privilege-escalation'
- -'attack.execution'
- -'attack.stealth'
- -'attack.t1574.001'
Logsource:
- category: image_load
- product: windows
Detection:
selection:
ImageLoaded|endswith:
'\goopdate.dll'
filter_main_generic:
ImageLoaded|startswith:
-'C:\Program Files (x86)\'
-'C:\Program Files\'
filter_optional_dropbox_installer_temp:
Image|contains|all:
-'\AppData\Local\Temp\GUM'
-'.tmp\Dropbox'
ImageLoaded|contains|all:
-'\AppData\Local\Temp\GUM'
-'.tmp\goopdate.dll'
filter_optional_googleupdate_temp:
Image|contains:
-'\AppData\Local\Temp\GUM'
-':\Windows\SystemTemp\GUM'
Image|endswith:
'.tmp\GoogleUpdate.exe'
ImageLoaded|contains:
-'\AppData\Local\Temp\GUM'
-':\Windows\SystemTemp\GUM'
condition:
selection and not 1 of filter_main_* and not 1 of filter_optional_*
Falsepositives:
-False positives are expected from Google Chrome installations running from user locations (AppData) and other custom locations. Apply additional filters accordingly.
-Other third party chromium browsers located in AppData
Level:
medium