Malicious DLL File Dropped in the Teams or OneDrive Folder

 Original Source: [Sigma source]
Title: Malicious DLL File Dropped in the Teams or OneDrive Folder
Status: test
Description:Detects creation of a malicious DLL file in the location where the OneDrive or Team applications Upon execution of the Teams or OneDrive application, the dropped malicious DLL file ("iphlpapi.dll") is sideloaded
References:
  -https://blog.cyble.com/2022/07/27/targeted-attacks-being-carried-out-via-dll-sideloading/
Author: frack113
Date: 2022-08-12
modified:None
Tags:
  • -'attack.persistence'
  • -'attack.privilege-escalation'
  • -'attack.execution'
  • -'attack.stealth'
  • -'attack.t1574.001'
Logsource:
  • category: file_event
  • product: windows
Detection:
  selection:
    TargetFilename|contains|all:
      -'iphlpapi.dll'
      -'\AppData\Local\Microsoft'

  condition:selection
Falsepositives:
  -Unknown
Level: high