Potential DLL Sideloading Of KeyScramblerIE.DLL Via KeyScrambler.EXE

 Original Source: [Sigma source]
Title: Potential DLL Sideloading Of KeyScramblerIE.DLL Via KeyScrambler.EXE
Status: test
Description:Detects potential DLL side loading of "KeyScramblerIE.dll" by "KeyScrambler.exe". Various threat actors and malware have been found side loading a masqueraded "KeyScramblerIE.dll" through "KeyScrambler.exe".
References:
  -https://thehackernews.com/2024/03/two-chinese-apt-groups-ramp-up-cyber.html
  -https://csirt-cti.net/2024/02/01/stately-taurus-continued-new-information-on-cyberespionage-attacks-against-myanmar-military-junta/
  -https://bazaar.abuse.ch/sample/5cb9876681f78d3ee8a01a5aaa5d38b05ec81edc48b09e3865b75c49a2187831/
  -https://twitter.com/Max_Mal_/status/1775222576639291859
  -https://twitter.com/DTCERT/status/1712785426895839339
Author: Swachchhanda Shrawan Poudel
Date: 2024-04-15
modified:None
Tags:
  • -'attack.persistence'
  • -'attack.privilege-escalation'
  • -'attack.execution'
  • -'attack.stealth'
  • -'attack.t1574.001'
Logsource:
  • category: image_load
  • product: windows
Detection:
  selection:
    Image|endswith:
      -'\KeyScrambler.exe'
      -'\KeyScramblerLogon.exe'

    ImageLoaded|endswith: '\KeyScramblerIE.dll'
  filter_main_legitimate_path:
    Image|contains:
      -'C:\Program Files (x86)\KeyScrambler\'
      -'C:\Program Files\KeyScrambler\'

    ImageLoaded|contains:
      -'C:\Program Files (x86)\KeyScrambler\'
      -'C:\Program Files\KeyScrambler\'

  filter_main_signature:
    Signature: 'QFX Software Corporation'
    SignatureStatus: 'Valid'
  condition:selection and not 1 of filter_main_*
Falsepositives:
  -Unknown
Level: high