Windows DLL Sideloading via ImageLoaded from ProgramShared, ProgramData, and ARM paths
Alerts on Windows processes loading DLLs from targeted ProgramShared/ProgramData paths consistent with DLL sideloading.
FreeUnreviewedSigmahighv1
windows-dll-sideloading-via-imageloaded-from-programshared-programdata-and-arm-p-24007168
title: Windows DLL Sideloading via ImageLoaded from ProgramShared, ProgramData, and ARM paths
id: 7a2fcf7f-c1a3-4f1d-8835-7735a7b3702d
status: test
description: This rule flags DLL sideloading behavior where a legitimate-looking EXE loads a DLL from specific, uncommon disk locations under ProgramShared, ProgramData, Oracle Java, and Adobe ARM directories. Such activity can indicate an attacker placing trojanized DLLs to hijack process execution without altering the original executable. Detection relies on image load telemetry showing the Image path and the corresponding ImageLoaded value matched by the rule’s known pairs.
references:
- https://www.welivesecurity.com/en/eset-research/lazarus-luring-employees-trojanized-coding-challenges-case-spanish-aerospace-company/
- https://www.bleepingcomputer.com/news/security/lazarus-hackers-breach-aerospace-firm-with-new-lightlesscan-malware/
- https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2023/TA/Lazarus/image_load_apt_lazarus_side_load_activity.yml
author: Thurein Oo, Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2023-10-18
tags:
- attack.privilege-escalation
- attack.persistence
- attack.execution
- attack.stealth
- attack.t1574.001
- attack.g0032
- detection.emerging-threats
logsource:
product: windows
category: image_load
detection:
selection_mscoree:
Image: C:\ProgramShared\PresentationHost.exe
ImageLoaded: :\ProgramShared\mscoree.dll
selection_colorui:
Image: C:\ProgramData\Adobe\colorcpl.exe
ImageLoaded: C:\ProgramData\Adobe\colorui.dll
selection_mapistub:
Image: C:\ProgramData\Oracle\Java\fixmapi.exe
ImageLoaded: C:\ProgramData\Oracle\Java\mapistub.dll
selection_hid:
Image: C:\ProgramData\Adobe\ARM\tabcal.exe
ImageLoaded: C:\ProgramData\Adobe\ARM\HID.dll
condition: 1 of selection_*
falsepositives:
- Unlikely
level: high
license: DRL-1.1
related:
- id: 24007168-a26b-4049-90d0-ce138e13a5cf
type: derived
What it detects
This rule flags DLL sideloading behavior where a legitimate-looking EXE loads a DLL from specific, uncommon disk locations under ProgramShared, ProgramData, Oracle Java, and Adobe ARM directories. Such activity can indicate an attacker placing trojanized DLLs to hijack process execution without altering the original executable. Detection relies on image load telemetry showing the Image path and the corresponding ImageLoaded value matched by the rule’s known pairs.
Known false positives
- Unlikely
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.