Windows Process Creation: Suspicious PlugX-Side-Loading Executables from Uncommon Paths

Alerts on execution of PlugX-related helper binaries from atypical paths, excluding common legitimate directories.

FreeUnreviewedSigmahighv1
title: "Windows Process Creation: Suspicious PlugX-Side-Loading Executables from Uncommon Paths"
id: 74173130-ad56-4d2c-8bc6-f944c677d081
status: test
description: This rule flags Windows process creation events where an executable associated with PlugX-style DLL side loading is launched from an uncommon location. Attackers may use these binaries to blend into legitimate execution patterns while loading malicious DLLs. The detection relies on process creation telemetry, matching executable image filenames and excluding known benign install paths via specific directory allowlists.
references:
  - http://www.hexacorn.com/blog/2016/03/10/beyond-good-ol-run-key-part-36/
  - https://countuponsecurity.com/2017/06/07/threat-hunting-in-the-enterprise-with-appcompatprocessor/
  - https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2017/Malware/PlugX/proc_creation_win_malware_plugx_susp_exe_locations.yml
author: Florian Roth (Nextron Systems), Huntrule Team
date: 2017-06-12
modified: 2023-02-03
tags:
  - attack.privilege-escalation
  - attack.persistence
  - attack.execution
  - attack.stealth
  - attack.s0013
  - attack.t1574.001
  - detection.emerging-threats
logsource:
  category: process_creation
  product: windows
detection:
  selection_cammute:
    Image|endswith: \CamMute.exe
  filter_cammute:
    Image|contains:
      - \Lenovo\Communication Utility\
      - \Lenovo\Communications Utility\
  selection_chrome_frame:
    Image|endswith: \chrome_frame_helper.exe
  filter_chrome_frame:
    Image|contains: \Google\Chrome\application\
  selection_devemu:
    Image|endswith: \dvcemumanager.exe
  filter_devemu:
    Image|contains: \Microsoft Device Emulator\
  selection_gadget:
    Image|endswith: \Gadget.exe
  filter_gadget:
    Image|contains: \Windows Media Player\
  selection_hcc:
    Image|endswith: \hcc.exe
  filter_hcc:
    Image|contains: \HTML Help Workshop\
  selection_hkcmd:
    Image|endswith: \hkcmd.exe
  filter_hkcmd:
    Image|contains:
      - \System32\
      - \SysNative\
      - \SysWow64\
  selection_mc:
    Image|endswith: \Mc.exe
  filter_mc:
    Image|contains:
      - \Microsoft Visual Studio
      - \Microsoft SDK
      - \Windows Kit
  selection_msmpeng:
    Image|endswith: \MsMpEng.exe
  filter_msmpeng:
    Image|contains:
      - \Microsoft Security Client\
      - \Windows Defender\
      - \AntiMalware\
  selection_msseces:
    Image|endswith: \msseces.exe
  filter_msseces:
    Image|contains:
      - \Microsoft Security Center\
      - \Microsoft Security Client\
      - \Microsoft Security Essentials\
  selection_oinfo:
    Image|endswith: \OInfoP11.exe
  filter_oinfo:
    Image|contains: \Common Files\Microsoft Shared\
  selection_oleview:
    Image|endswith: \OleView.exe
  filter_oleview:
    Image|contains:
      - \Microsoft Visual Studio
      - \Microsoft SDK
      - \Windows Kit
      - \Windows Resource Kit\
  selection_rc:
    Image|endswith: \rc.exe
  filter_rc:
    Image|contains:
      - \Microsoft Visual Studio
      - \Microsoft SDK
      - \Windows Kit
      - \Windows Resource Kit\
      - \Microsoft.NET\
  condition: ( selection_cammute and not filter_cammute ) or ( selection_chrome_frame and not filter_chrome_frame ) or ( selection_devemu and not filter_devemu ) or ( selection_gadget and not filter_gadget ) or ( selection_hcc and not filter_hcc ) or ( selection_hkcmd and not filter_hkcmd ) or ( selection_mc and not filter_mc ) or ( selection_msmpeng and not filter_msmpeng ) or ( selection_msseces and not filter_msseces ) or ( selection_oinfo and not filter_oinfo ) or ( selection_oleview and not filter_oleview ) or ( selection_rc and not filter_rc )
falsepositives:
  - Unknown
level: high
license: DRL-1.1
related:
  - id: aeab5ec5-be14-471a-80e8-e344418305c2
    type: derived

What it detects

This rule flags Windows process creation events where an executable associated with PlugX-style DLL side loading is launched from an uncommon location. Attackers may use these binaries to blend into legitimate execution patterns while loading malicious DLLs. The detection relies on process creation telemetry, matching executable image filenames and excluding known benign install paths via specific directory allowlists.

Known false positives

  • Unknown

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.