Potential 7za.DLL Sideloading

 Original Source: [Sigma source]
Title: Potential 7za.DLL Sideloading
Status: test
Description:Detects potential DLL sideloading of "7za.dll"
References:
  -https://www.gov.pl/attachment/ee91f24d-3e67-436d-aa50-7fa56acf789d
Author: X__Junior
Date: 2023-06-09
modified:None
Tags:
  • -'attack.persistence'
  • -'attack.privilege-escalation'
  • -'attack.execution'
  • -'attack.stealth'
  • -'attack.t1574.001'
Logsource:
  • category: image_load
  • product: windows
Detection:
  selection:
    ImageLoaded|endswith: '\7za.dll'
  filter_main_legit_path:
    Image|startswith:
      -'C:\Program Files (x86)\'
      -'C:\Program Files\'

    ImageLoaded|startswith:
      -'C:\Program Files (x86)\'
      -'C:\Program Files\'

  condition:selection and not 1 of filter_main_*
Falsepositives:
  -Legitimate third party application located in "AppData" may leverage this DLL to offer 7z compression functionality and may generate false positives. Apply additional filters as needed.
Level: low