Potential COLDSTEEL Persistence Service DLL Load

Last updated on:

About the rule

Rule Type

Standard

Rule Description

Detects a suspicious DLL load by an "svchost" process based on location and name that might be related to ColdSteel RAT. This DLL location and name has been seen used by ColdSteel as the service DLL for its persistence mechanism

Severity

Trouble

Rule Requirement

Criteria

Action1: actionname = "sa_imageloaded" AND PROCESSNAME endswith "\svchost.exe" AND OBJECTNAME endswith "\AppData\Roaming\newdev.dll" select Action1.HOSTNAME,Action1.MESSAGE,Action1.PROCESSNAME,Action1.PRODUCT_NAME,Action1.OBJECTNAME

Detection

Execution Mode

realtime

Log Sources

Windows

Author

Nasreddine Bencherchali (Nextron Systems)