Potential Vcruntime140 DLL Sideloading

 Original Source: [Sigma source]
Title: Potential Vcruntime140 DLL Sideloading
Status: experimental
Description:Detects potential DLL sideloading of vcruntime140.dll, a common C++ runtime library. Threat actors have been observed using DLL sideloading techniques to load malicious payloads under the guise of legitimate applications such as SqlWriter, SqlDumper etc. Notably, APT29 has been documented leveraging WinELOADER to sideload vcruntime140.dll for executing malicious code.
References:
  -https://www.mandiant.com/resources/blog/apt29-wineloader-german-political-parties
  -https://www.zscaler.com/blogs/security-research/european-diplomats-targeted-spikedwine-wineloader
  -https://www.nextron-systems.com/2023/09/15/detecting-janelarat-with-yara-and-thor/
Author: Swachchhanda Shrawan Poudel (Nextron Systems)
Date: 2026-01-12
modified:2026-05-18
Tags:
  • -'attack.persistence'
  • -'attack.privilege-escalation'
  • -'attack.execution'
  • -'attack.stealth'
  • -'attack.t1574.001'
Logsource:
  • category: image_load
  • product: windows
Detection:
  selection:
    ImageLoaded|endswith: '\vcruntime140.dll'
  filter_main_legitimate_path:
    ImageLoaded|startswith:
      -'C:\Windows\System32\'
      -'C:\Windows\SysWOW64\'
      -'C:\Program Files\'
      -'C:\Program Files (x86)\'

  filter_main_legitimate_signer:
    Signed: 'True'
    SignatureStatus: 'Valid'
    Description|endswith: 'C Runtime Library'
  filter_optional_onedrive:
    Image|startswith: 'C:\Users\'
    Image|contains: '\AppData\Local\Microsoft\OneDrive\'
  condition:selection and not 1 of filter_main_* and not 1 of filter_optional_*
Falsepositives:
  -Unknown
Level: high