Title:Potential DLL Sideloading Of Libcurl.DLL Via GUP.EXE Status:test Description:Detects potential DLL sideloading of "libcurl.dll" by the "gup.exe" process from an uncommon location References: -https://labs.withsecure.com/publications/fin7-target-veeam-servers Author: Nasreddine Bencherchali (Nextron Systems) Date: 2023-05-05 modified:None Tags:
-'attack.persistence'
-'attack.privilege-escalation'
-'attack.execution'
-'attack.stealth'
-'attack.t1574.001'
Logsource:
category: image_load
product: windows
Detection: selection: Image|endswith:
'\gup.exe' ImageLoaded|endswith:
'\libcurl.dll' filter_main_notepad_plusplus: Image|endswith:
'\Notepad++\updater\GUP.exe' condition:selection and not 1 of filter_main_* Falsepositives:
-Unknown Level:medium