Potential DLL Sideloading Via ClassicExplorer32.dll

 Original Source: [Sigma source]
Title: Potential DLL Sideloading Via ClassicExplorer32.dll
Status: test
Description:Detects potential DLL sideloading using ClassicExplorer32.dll from the Classic Shell software
References:
  -https://blogs.blackberry.com/en/2022/12/mustang-panda-uses-the-russian-ukrainian-war-to-attack-europe-and-asia-pacific-targets
  -https://app.any.run/tasks/6d8cabb0-dcda-44b6-8050-28d6ce281687/
Author: frack113
Date: 2022-12-13
modified:None
Tags:
  • -'attack.persistence'
  • -'attack.privilege-escalation'
  • -'attack.execution'
  • -'attack.stealth'
  • -'attack.t1574.001'
Logsource:
  • category: image_load
  • product: windows
Detection:
  selection_classicexplorer:
    ImageLoaded|endswith: '\ClassicExplorer32.dll'
  filter_classicexplorer:
    ImageLoaded|startswith: 'C:\Program Files\Classic Shell\'
  condition:selection_classicexplorer and not filter_classicexplorer
Falsepositives:
  -Unknown
Level: medium