Potential DLL Sideloading Via DeviceEnroller.EXE

 Original Source: [Sigma source]
Title: Potential DLL Sideloading Via DeviceEnroller.EXE
Status: test
Description:Detects the use of the PhoneDeepLink parameter to potentially sideload a DLL file that does not exist. This non-existent DLL file is named "ShellChromeAPI.dll". Adversaries can drop their own renamed DLL and execute it via DeviceEnroller.exe using this parameter
References:
  -https://mobile.twitter.com/0gtweet/status/1564131230941122561
  -https://strontic.github.io/xcyclopedia/library/DeviceEnroller.exe-24BEF0D6B0ECED36BB41831759FDE18D.html
Author: @gott_cyber
Date: 2022-08-29
modified:2023-02-04
Tags:
  • -'attack.privilege-escalation'
  • -'attack.persistence'
  • -'attack.execution'
  • -'attack.stealth'
  • -'attack.t1574.001'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
Image|endswith:'\deviceenroller.exe' OriginalFileName:'deviceenroller.exe'   selection_cli:
    CommandLine|contains: '/PhoneDeepLink'
  condition:all of selection_*
Falsepositives:
  -Unknown
Level: medium