UAC Bypass With Fake DLL

 Original Source: [Sigma source]
Title: UAC Bypass With Fake DLL
Status: test
Description:Attempts to load dismcore.dll after dropping it
References:
  -https://steemit.com/utopian-io/@ah101/uac-bypassing-utility
Author: oscd.community, Dmitry Uchakin
Date: 2020-10-06
modified:2022-12-25
Tags:
  • -'attack.persistence'
  • -'attack.privilege-escalation'
  • -'attack.execution'
  • -'attack.stealth'
  • -'attack.t1548.002'
  • -'attack.t1574.001'
Logsource:
  • category: image_load
  • product: windows
Detection:
  selection:
    Image|endswith: '\dism.exe'
    ImageLoaded|endswith: '\dismcore.dll'
  filter:
    ImageLoaded: 'C:\Windows\System32\Dism\dismcore.dll'
  condition:selection and not filter
Falsepositives:
  -Actions of a legitimate telnet client
Level: high