Potential DLL Sideloading Via VMware Xfer

 Original Source: [Sigma source]
Title: Potential DLL Sideloading Via VMware Xfer
Status: test
Description:Detects loading of a DLL by the VMware Xfer utility from the non-default directory which may be an attempt to sideload arbitrary DLL
References:
  -https://www.sentinelone.com/labs/lockbit-ransomware-side-loads-cobalt-strike-beacon-with-legitimate-vmware-utility/
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2022-08-02
modified:2023-02-17
Tags:
  • -'attack.privilege-escalation'
  • -'attack.persistence'
  • -'attack.execution'
  • -'attack.stealth'
  • -'attack.t1574.001'
Logsource:
  • product: windows
  • category: image_load
Detection:
  selection:
    Image|endswith: '\VMwareXferlogs.exe'
    ImageLoaded|endswith: '\glib-2.0.dll'
  filter:
    ImageLoaded|startswith: 'C:\Program Files\VMware\'
  condition:selection and not filter
Falsepositives:
  -Unlikely
Level: high