Suspicious Image Load of RstrtMgr.dll by Windows Process

Alerts on RstrtMgr.dll loading from suspicious path contexts using Windows image load telemetry.

FreeUnreviewedSigmahighv1
title: Suspicious Image Load of RstrtMgr.dll by Windows Process
id: a8c664f0-b1f1-4d92-b811-d65dd155e327
related:
  - id: 3669afd2-9891-4534-a626-e5cf03810a61
    type: derived
  - id: b48492dc-c5ef-4572-8dff-32bc241c15c8
    type: derived
status: test
description: This rule flags when a Windows process loads the Restart Manager library file RstrtMgr.dll, focusing on DLLs loaded from user- and staging-like paths. Attackers may use Restart Manager to interfere with other processes, such as killing or disrupting locked files prior to impact activity, or as part of anti-analysis behavior. It relies on image load telemetry that records the loaded DLL path/name and the original file name, matching the RstrtMgr.dll indicators plus specific substrings in the image path.
references:
  - https://www.crowdstrike.com/blog/windows-restart-manager-part-1/
  - https://www.crowdstrike.com/blog/windows-restart-manager-part-2/
  - https://web.archive.org/web/20231221193106/https://www.swascan.com/cactus-ransomware-malware-analysis/
  - https://taiwan.postsen.com/business/88601/Hamas-hackers-use-data-destruction-software-BiBi-which-consumes-a-lot-of-processor-resources-to-wipe-Windows-computer-data--iThome.html
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/image_load/image_load_dll_rstrtmgr_suspicious_load.yml
author: Luc Génaux, Huntrule Team
date: 2023-11-28
tags:
  - attack.impact
  - attack.defense-impairment
  - attack.t1486
  - attack.t1685
logsource:
  category: image_load
  product: windows
detection:
  selection_img:
    - ImageLoaded|endswith: \RstrtMgr.dll
    - OriginalFileName: RstrtMgr.dll
  selection_folders_1:
    Image|contains:
      - :\Perflogs\
      - :\Users\Public\
      - \Temporary Internet
  selection_folders_2:
    - Image|contains|all:
        - :\Users\
        - \Favorites\
    - Image|contains|all:
        - :\Users\
        - \Favourites\
    - Image|contains|all:
        - :\Users\
        - \Contacts\
  condition: selection_img and 1 of selection_folders_*
falsepositives:
  - Processes related to software installation
level: high
license: DRL-1.1

What it detects

This rule flags when a Windows process loads the Restart Manager library file RstrtMgr.dll, focusing on DLLs loaded from user- and staging-like paths. Attackers may use Restart Manager to interfere with other processes, such as killing or disrupting locked files prior to impact activity, or as part of anti-analysis behavior. It relies on image load telemetry that records the loaded DLL path/name and the original file name, matching the RstrtMgr.dll indicators plus specific substrings in the image path.

Known false positives

  • Processes related to software installation

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.