Potential COLDSTEEL Persistence Service DLL Load
Last updated on:
In this page
About the rule
Rule Type
Standard
Rule Description
Detects a suspicious DLL load by an "svchost" process based on location and name that might be related to ColdSteel RAT. This DLL location and name has been seen used by ColdSteel as the service DLL for its persistence mechanism
Severity
Trouble
Rule Requirement
Criteria
Action1: actionname = "sa_imageloaded" AND PROCESSNAME endswith "\svchost.exe" AND OBJECTNAME endswith "\AppData\Roaming\newdev.dll" select Action1.HOSTNAME,Action1.MESSAGE,Action1.PROCESSNAME,Action1.PRODUCT_NAME,Action1.OBJECTNAME
Detection
Execution Mode
realtime
Log Sources
Windows
Author
Nasreddine Bencherchali (Nextron Systems)


