Potential Initial Access via DLL Search Order Hijacking

 Original Source: [Sigma source]
Title: Potential Initial Access via DLL Search Order Hijacking
Status: test
Description:Detects attempts to create a DLL file to a known desktop application dependencies folder such as Slack, Teams or OneDrive and by an unusual process. This may indicate an attempt to load a malicious module via DLL search order hijacking.
References:
  -https://github.com/elastic/protections-artifacts/commit/746086721fd385d9f5c6647cada1788db4aea95f#diff-5d46dd4ac6866b4337ec126be8cee0e115467b3e8703794ba6f6df6432c806bc
  -https://posts.specterops.io/automating-dll-hijack-discovery-81c4295904b0
Author: Tim Rauch (rule), Elastic (idea)
Date: 2022-10-21
modified:None
Tags:
  • -'attack.privilege-escalation'
  • -'attack.persistence'
  • -'attack.execution'
  • -'attack.stealth'
  • -'attack.t1566'
  • -'attack.t1566.001'
  • -'attack.initial-access'
  • -'attack.t1574'
  • -'attack.t1574.001'
Logsource:
  • product: windows
  • category: file_event
Detection:
  selection:
    Image|endswith:
      -'\winword.exe'
      -'\excel.exe'
      -'\powerpnt.exe'
      -'\MSACCESS.EXE'
      -'\MSPUB.EXE'
      -'\fltldr.exe'
      -'\cmd.exe'
      -'\certutil.exe'
      -'\mshta.exe'
      -'\cscript.exe'
      -'\wscript.exe'
      -'\curl.exe'
      -'\powershell.exe'
      -'\pwsh.exe'

    TargetFilename|endswith: '.dll'
    TargetFilename|contains|all:
      -'\Users\'
      -'\AppData\'

    TargetFilename|contains:
      -'\Microsoft\OneDrive\'
      -'\Microsoft OneDrive\'
      -'\Microsoft\Teams\'
      -'\Local\slack\app-'
      -'\Local\Programs\Microsoft VS Code\'

  filter:
    Image|endswith: '\cmd.exe'
    TargetFilename|contains|all:
      -'\Users\'
      -'\AppData\'
      -'\Microsoft\OneDrive\'
      -'\api-ms-win-core-'

  condition:selection and not filter
Falsepositives:
  -Unknown
Level: medium