Fax Service DLL Search Order Hijack

 Original Source: [Sigma source]
Title: Fax Service DLL Search Order Hijack
Status: test
Description:The Fax service attempts to load ualapi.dll, which is non-existent. An attacker can then (side)load their own malicious DLL using this service.
References:
  -https://windows-internals.com/faxing-your-way-to-system/
Author: NVISO
Date: 2020-05-04
modified:2022-06-02
Tags:
  • -'attack.privilege-escalation'
  • -'attack.persistence'
  • -'attack.execution'
  • -'attack.stealth'
  • -'attack.t1574.001'
Logsource:
  • category: image_load
  • product: windows
Detection:
  selection:
    Image|endswith: '\fxssvc.exe'
    ImageLoaded|endswith: 'ualapi.dll'
  filter:
    ImageLoaded|startswith: 'C:\Windows\WinSxS\'
  condition:selection and not filter
Falsepositives:
  -Unlikely
Level: high