Analytics BIOC Low

Svchost.exe loads a rare unsigned module

Svchost.exe loads a rare unsigned module, which can indicate an attacker's malicious service execution.

Module:
Platform Analytics
Data source:
XDR Agent
ATT&CK tactics: Defense Evasion (TA0005) Persistence (TA0003)
ATT&CK techniques: Masquerading: Masquerade Task or Service (T1036.004) Create or Modify System Process: Windows Service (T1543.003)
Detector tags: Malicious Service Analytics
Attacker's goals:

Evading detections by running code from a signed Microsoft executable.

Investigative actions:

Check whether the loaded module with the corresponding hash is benign and if this was a desired behavior as part of its normal execution flow. Go to the 'Services' registry key and investigate its sub keys to find the service associated with the loaded dll.

Test period:
N/A (single event)
Deduplication:
1 Day