Potential Arbitrary DLL Load Using Winword

 Original Source: [Sigma source]
Title: Potential Arbitrary DLL Load Using Winword
Status: test
Description:Detects potential DLL sideloading using the Microsoft Office winword process via the '/l' flag.
References:
  -https://github.com/D4Vinci/One-Lin3r/blob/9fdfa5f0b9c698dfbd4cdfe7d2473192777ae1c6/one_lin3r/core/liners/windows/cmd/dll_loader_word.py
Author: Victor Sergeev, oscd.community
Date: 2020-10-09
modified:2023-03-29
Tags:
  • -'attack.stealth'
  • -'attack.t1202'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
Image|endswith:'\WINWORD.exe' OriginalFileName:'WinWord.exe'   selection_dll:
    CommandLine|contains|all:
      -'/l '
      -'.dll'

  condition:all of selection_*
Falsepositives:
  -Unknown
Level: medium