Suspicious Image Load of RstrtMgr.dll by Windows Process
Alerts on RstrtMgr.dll loading from suspicious path contexts using Windows image load telemetry.
FreeUnreviewedSigmahighv1
suspicious-image-load-of-rstrtmgr-dll-by-windows-process-b48492dc
title: Suspicious Image Load of RstrtMgr.dll by Windows Process
id: a8c664f0-b1f1-4d92-b811-d65dd155e327
related:
- id: 3669afd2-9891-4534-a626-e5cf03810a61
type: derived
- id: b48492dc-c5ef-4572-8dff-32bc241c15c8
type: derived
status: test
description: This rule flags when a Windows process loads the Restart Manager library file RstrtMgr.dll, focusing on DLLs loaded from user- and staging-like paths. Attackers may use Restart Manager to interfere with other processes, such as killing or disrupting locked files prior to impact activity, or as part of anti-analysis behavior. It relies on image load telemetry that records the loaded DLL path/name and the original file name, matching the RstrtMgr.dll indicators plus specific substrings in the image path.
references:
- https://www.crowdstrike.com/blog/windows-restart-manager-part-1/
- https://www.crowdstrike.com/blog/windows-restart-manager-part-2/
- https://web.archive.org/web/20231221193106/https://www.swascan.com/cactus-ransomware-malware-analysis/
- https://taiwan.postsen.com/business/88601/Hamas-hackers-use-data-destruction-software-BiBi-which-consumes-a-lot-of-processor-resources-to-wipe-Windows-computer-data--iThome.html
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/image_load/image_load_dll_rstrtmgr_suspicious_load.yml
author: Luc Génaux, Huntrule Team
date: 2023-11-28
tags:
- attack.impact
- attack.defense-impairment
- attack.t1486
- attack.t1685
logsource:
category: image_load
product: windows
detection:
selection_img:
- ImageLoaded|endswith: \RstrtMgr.dll
- OriginalFileName: RstrtMgr.dll
selection_folders_1:
Image|contains:
- :\Perflogs\
- :\Users\Public\
- \Temporary Internet
selection_folders_2:
- Image|contains|all:
- :\Users\
- \Favorites\
- Image|contains|all:
- :\Users\
- \Favourites\
- Image|contains|all:
- :\Users\
- \Contacts\
condition: selection_img and 1 of selection_folders_*
falsepositives:
- Processes related to software installation
level: high
license: DRL-1.1
What it detects
This rule flags when a Windows process loads the Restart Manager library file RstrtMgr.dll, focusing on DLLs loaded from user- and staging-like paths. Attackers may use Restart Manager to interfere with other processes, such as killing or disrupting locked files prior to impact activity, or as part of anti-analysis behavior. It relies on image load telemetry that records the loaded DLL path/name and the original file name, matching the RstrtMgr.dll indicators plus specific substrings in the image path.
Known false positives
- Processes related to software installation
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.