DLL Sideloading by VMware Xfer Utility

 Original Source: [Sigma source]
Title: DLL Sideloading by VMware Xfer Utility
Status: test
Description:Detects execution of VMware Xfer utility (VMwareXferlogs.exe) from the non-default directory which may be an attempt to sideload arbitrary DLL
References:
  -https://www.sentinelone.com/labs/lockbit-ransomware-side-loads-cobalt-strike-beacon-with-legitimate-vmware-utility/
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2022-08-02
modified:None
Tags:
  • -'attack.privilege-escalation'
  • -'attack.persistence'
  • -'attack.execution'
  • -'attack.stealth'
  • -'attack.t1574.001'
Logsource:
  • product: windows
  • category: process_creation
Detection:
  selection:
    Image|endswith: '\VMwareXferlogs.exe'
  filter:
    Image|startswith: 'C:\Program Files\VMware\'
  condition:selection and not filter
Falsepositives:
  -Unlikely
Level: high