Windows DLL Loading of C:\Windows\oci.dll by msdtc.exe
Flags msdtc.exe loading C:\Windows\oci.dll, consistent with Pingback backdoor DLL loading behavior.
- Product
- windows
- Category
- image_load
- Author
- Bhabesh Raj (SigmaHQ), DRL 1.1
- Published
- 2021-05-05
- Updated
- 2026-07-31
ATT&CK techniques
Execution → Defense EvasionRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags a specific Windows process image load event where msdtc.exe loads C:\Windows\oci.dll. Such DLL load activity may indicate stealthy execution or backdoor-related behavior, since attackers often leverage legitimate Windows binaries to bring in malicious or unexpected libraries. It relies on telemetry that records loaded modules for image load events on Windows.
Reporting behind it
- trustwave.comhttps://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/backdoor-at-the-end-of-the-icmp-tunnel
- app.any.runhttps://app.any.run/tasks/4a54c651-b70b-4b72-84d7-f34d301d6406
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2021/Malware/Pingback/image_load_malware_pingback_backdoor.yml
Changelog
v5- v5Candidate ingested via manual entry.2026-07-31
- v4Candidate ingested via manual entry.2026-07-31
- v3Candidate ingested via manual entry.2026-07-31
- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Windows DLL Loading of C:\Windows\oci.dll by msdtc.exe
id: 6088fb5b-a151-4b58-901e-b9df88a14080
related:
- id: 35a7dc42-bc6f-46e0-9f83-81f8e56c8d4b
type: similar
- id: b2400ffb-7680-47c0-b08a-098a7de7e7a9
type: similar
- id: 35a7dc42-bc6f-46e0-9f83-81f8e56c8d4b
type: derived
status: test
description: This rule flags a specific Windows process image load event where msdtc.exe loads C:\Windows\oci.dll. Such DLL load activity may indicate stealthy execution or backdoor-related behavior, since attackers often leverage legitimate Windows binaries to bring in malicious or unexpected libraries. It relies on telemetry that records loaded modules for image load events on Windows.
references:
- https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/backdoor-at-the-end-of-the-icmp-tunnel
- https://app.any.run/tasks/4a54c651-b70b-4b72-84d7-f34d301d6406
- https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2021/Malware/Pingback/image_load_malware_pingback_backdoor.yml
author: Bhabesh Raj, Huntrule Team
date: 2021-05-05
modified: 2023-02-17
tags:
- attack.privilege-escalation
- attack.persistence
- attack.execution
- attack.stealth
- attack.t1574.001
- detection.emerging-threats
logsource:
product: windows
category: image_load
detection:
selection:
Image|endswith: \msdtc.exe
ImageLoaded: C:\Windows\oci.dll
condition: selection
falsepositives:
- Unlikely
level: high
license: DRL-1.1