Aruba Network Service Potential DLL Sideloading

 Original Source: [Sigma source]
Title: Aruba Network Service Potential DLL Sideloading
Status: test
Description:Detects potential DLL sideloading activity via the Aruba Networks Virtual Intranet Access "arubanetsvc.exe" process using DLL Search Order Hijacking
References:
  -https://twitter.com/wdormann/status/1616581559892545537?t=XLCBO9BziGzD7Bmbt8oMEQ&s=09
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2023-01-22
modified:2023-03-15
Tags:
  • -'attack.privilege-escalation'
  • -'attack.persistence'
  • -'attack.execution'
  • -'attack.stealth'
  • -'attack.t1574.001'
Logsource:
  • category: image_load
  • product: windows
Detection:
  selection:
    Image|endswith: '\arubanetsvc.exe'
    ImageLoaded|endswith:
      -'\wtsapi32.dll'
      -'\msvcr100.dll'
      -'\msvcp100.dll'
      -'\dbghelp.dll'
      -'\dbgcore.dll'
      -'\wininet.dll'
      -'\iphlpapi.dll'
      -'\version.dll'
      -'\cryptsp.dll'
      -'\cryptbase.dll'
      -'\wldp.dll'
      -'\profapi.dll'
      -'\sspicli.dll'
      -'\winsta.dll'
      -'\dpapi.dll'

  filter:
    ImageLoaded|startswith:
      -'C:\Windows\System32\'
      -'C:\Windows\SysWOW64\'
      -'C:\Windows\WinSxS\'

  condition:selection and not filter
Falsepositives:
  -Unknown
Level: high