title: Potential DLL Sideloading Of Libcurl.DLL Via GUP.EXE id: e49b5745-1064-4ac1-9a2e-f687bc2dd37e status: test description: Detects potential DLL sideloading of "libcurl.dll" by the "gup.exe" process from an uncommon location references: - https://labs.withsecure.com/publications/fin7-target-veeam-servers author: Nasreddine Bencherchali (Nextron Systems) date: 2023-05-05 tags: - attack.persistence - attack.privilege-escalation - attack.execution - attack.stealth - attack.t1574.001 logsource: category: image_load product: windows detection: selection: Image|endswith: '\gup.exe' ImageLoaded|endswith: '\libcurl.dll' filter_main_notepad_plusplus: Image|endswith: '\Notepad++\updater\GUP.exe' condition: selection and not 1 of filter_main_* falsepositives: - Unknown level: medium