Title:Fax Service DLL Search Order Hijack Status:test Description:The Fax service attempts to load ualapi.dll, which is non-existent. An attacker can then (side)load their own malicious DLL using this service. References: -https://windows-internals.com/faxing-your-way-to-system/ Author: NVISO Date: 2020-05-04 modified:2022-06-02 Tags:
-'attack.privilege-escalation'
-'attack.persistence'
-'attack.execution'
-'attack.stealth'
-'attack.t1574.001'
Logsource:
category: image_load
product: windows
Detection: selection: Image|endswith:
'\fxssvc.exe' ImageLoaded|endswith:
'ualapi.dll' filter: ImageLoaded|startswith:
'C:\Windows\WinSxS\' condition:selection and not filter Falsepositives:
-Unlikely Level:high