DLL Sideloading Of ShellChromeAPI.DLL

 Original Source: [Sigma source]
Title: DLL Sideloading Of ShellChromeAPI.DLL
Status: test
Description:Detects processes loading the non-existent DLL "ShellChromeAPI". One known example is the "DeviceEnroller" binary in combination with the "PhoneDeepLink" flag tries to load this DLL. Adversaries can drop their own renamed DLL and execute it via DeviceEnroller.exe using this parameter
References:
  -https://mobile.twitter.com/0gtweet/status/1564131230941122561
  -https://strontic.github.io/xcyclopedia/library/DeviceEnroller.exe-24BEF0D6B0ECED36BB41831759FDE18D.html
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2022-12-01
modified:None
Tags:
  • -'attack.persistence'
  • -'attack.privilege-escalation'
  • -'attack.execution'
  • -'attack.stealth'
  • -'attack.t1574.001'
Logsource:
  • category: image_load
  • product: windows
Detection:
  selection:
    ImageLoaded|endswith: '\ShellChromeAPI.dll'
  condition:selection
Falsepositives:
  -Unknown
Level: high