Suspicious version.dll Sideloading via ADExplorer

PremiumReviewedSigma · High · v1
Product
windows
Category
image_load
Author
HuntRule
Published
2026-09-27
Updated
2026-09-27

ATT&CK techniques

Execution → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

  14. Impact

What it detects

This rule detects the Sysinternals ADExplorer binary loading a version.dll from outside the System32 directory, the DLL search order hijack the actor used to sideload malicious code. A trusted signed tool loading a non-system version.dll from its working directory is a classic sideloading pattern rather than normal execution.

Related detections9 linkedT1574.001 — drag to rearrange
Suspicious jli.dll Sideloading by Non-Java Trusted Binary
Malicious DLL Sideload via SentinelBrowserNativeHost
Suspicious Application Config File Dropped Beside Trusted .NET Binary for App Domain Manager Injection
Suspicious Acrobat.exe Loading Co-located DLL from ProgramData
Suspicious IntelAudioService Execution with StateRepository Arguments via SPECTRALVIPER
Malicious Kazuar DLL Side-Loading via Renamed Host Binaries
Malicious Lazarus DLL Side-Loading via Colorcpl from ProgramData (via process_creation)
Malicious Lazarus DLL Side-Loading via PresentationHost from Non-Standard Path (via process_creation)
Suspicious msvc_4.dll Side-Load from Typosquatted NVIDlA Directory via Image Load
Suspicious version.dll Sideloading via ADExplorer
Pivot detection · T1574.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.