Potential OleView and aclui.dll Side-Loading on Windows

Alerts on OleView.exe loading aclui.dll on Windows, excluding common benign paths to highlight potential DLL side-loading.

FreeUnreviewedSigmahighv1
title: Potential OleView and aclui.dll Side-Loading on Windows
id: 5d5ac63e-e93e-4e3d-8968-a01354d9906e
status: test
description: This rule flags Windows processes that load a DLL named aclui.dll when the image path ends with OleView.exe, excluding activity from several known OleView installation locations and Windows Resource Kit paths. DLL side-loading is a stealthy tactic attackers can use to execute malicious code by making a targeted application load an attacker-controlled or unexpected DLL. The detection relies on image load telemetry (Image and ImageLoaded) and, when present, the Signed field to filter for signed execution.
references:
  - https://research.checkpoint.com/2024/raspberry-robin-keeps-riding-the-wave-of-endless-1-days/
  - https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/
  - https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/
  - https://www.hexacorn.com/blog/2016/03/10/beyond-good-ol-run-key-part-36/
  - https://strontic.github.io/xcyclopedia/library/aclui.dll-F883E9CA757B622B032FDCA5BF33D0DF.html
  - https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2024/Malware/Raspberry-Robin/image_load_malware_raspberry_robin_side_load_aclui_oleview.yml
author: Swachchhanda Shrawan Poudel, Huntrule Team
date: 2024-07-31
tags:
  - attack.persistence
  - attack.privilege-escalation
  - attack.execution
  - attack.stealth
  - attack.t1574.001
  - detection.emerging-threats
logsource:
  category: image_load
  product: windows
detection:
  selection:
    Image|endswith: \OleView.exe
    ImageLoaded|endswith: \aclui.dll
  filter_main_legit_oleview_paths:
    Image|startswith:
      - C:\Program Files (x86)\Windows Kits\
      - C:\Program Files\Microsoft SDKs\
  filter_optional_known_oleview_paths:
    Image|contains: \Windows Resource Kit\
  filter_main_is_signed:
    Signed: "true"
  condition: selection and not 1 of filter_main_* and not 1 of filter_optional_*
falsepositives:
  - Unknown
level: high
license: DRL-1.1
related:
  - id: 0f3a9db2-c17a-480e-a723-d1f1c547ab6a
    type: derived

What it detects

This rule flags Windows processes that load a DLL named aclui.dll when the image path ends with OleView.exe, excluding activity from several known OleView installation locations and Windows Resource Kit paths. DLL side-loading is a stealthy tactic attackers can use to execute malicious code by making a targeted application load an attacker-controlled or unexpected DLL. The detection relies on image load telemetry (Image and ImageLoaded) and, when present, the Signed field to filter for signed execution.

Known false positives

  • Unknown

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.