Suspicious DLL Written to Explorer IconCache Path

PremiumReviewedSigma · High · v1
Product
windows
Category
file_event
Author
HuntRule
Published
2026-06-22
Updated
2026-08-28

ATT&CK techniques

Initial Access → Execution
  1. Recon

  2. Resource Dev

  3. Persistence

  4. Priv Esc

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects a DLL written to the Explorer icon cache directory using an iconcache prefixed name with a numeric suffix. In Operation ForumTroll a LNK triggered PowerShell chain dropped a payload DLL named iconcache_<4digits>.dll to this location as reported by Kaspersky. Legitimate icon cache files use the .db extension so a .dll in this path is a strong masquerading and payload staging indicator.

Related detections9 linkedT1204.002 — drag to rearrange
Ursnif C2 Proxy Traffic Identified by Base64 URI Encoding and .avi/.images Pattern
Windows process creation: Winword launching FLTLDR.exe exploitation behavior
Windows Process Creation: EQNEDT32.EXE Used as CVE-2017-11882 Exploit Dropper Parent
Windows: Winword spawning csc.exe indicative of CVE-2017-8759 exploitation
Suspicious Interlock Fake Updater Executable Execution
Malicious Office Application Loading a User-Path DLL via Regsvr32 or Rundll32 (via process_creation)
Suspicious Program Execution From a Mounted ISO or Disk Image (via process_creation)
SocGholish Fake Browser Update Script Execution (via process_creation)
Uncommon Executable Written to Startup Folder by WinRAR via CVE-2025-8088 Path Traversal (via file_event)
Suspicious DLL Written to Explorer IconCache Path
Pivot detection · T1204.002 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.