Potential DLL Sideloading Via comctl32.dll

 Original Source: [Sigma source]
Title: Potential DLL Sideloading Via comctl32.dll
Status: test
Description:Detects potential DLL sideloading using comctl32.dll to obtain system privileges
References:
  -https://github.com/binderlabs/DirCreate2System
  -https://github.com/sailay1996/awesome_windows_logical_bugs/blob/60cbb23a801f4c3195deac1cc46df27c225c3d07/dir_create2system.txt
Author: Nasreddine Bencherchali (Nextron Systems), Subhash Popuri (@pbssubhash)
Date: 2022-12-16
modified:2022-12-19
Tags:
  • -'attack.persistence'
  • -'attack.privilege-escalation'
  • -'attack.execution'
  • -'attack.stealth'
  • -'attack.t1574.001'
Logsource:
  • category: image_load
  • product: windows
Detection:
  selection:
    ImageLoaded|startswith:
      -'C:\Windows\System32\logonUI.exe.local\'
      -'C:\Windows\System32\werFault.exe.local\'
      -'C:\Windows\System32\consent.exe.local\'
      -'C:\Windows\System32\narrator.exe.local\'
      -'C:\windows\system32\wermgr.exe.local\'

    ImageLoaded|endswith: '\comctl32.dll'
  condition:selection
Falsepositives:
  -Unlikely
Level: high