title: Potential COLDSTEEL RAT File Indicators id: c708a93f-46b4-4674-a5b8-54aa6219c5fa status: test description: Detects the creation of a file named "dllhost.exe" in the "C:\users\public\Documents\" directory. Seen being used by the COLDSTEEL RAT in some of its variants. references: - https://www.ncsc.gov.uk/static-assets/documents/malware-analysis-reports/cold-steel/NCSC-MAR-Cold-Steel.pdf author: Nasreddine Bencherchali (Nextron Systems) date: 2023-04-30 tags: - attack.persistence - detection.emerging-threats - attack.stealth logsource: category: file_event product: windows detection: selection: TargetFilename: 'C:\users\public\Documents\dllhost.exe' condition: selection falsepositives: - Unknown level: high