BIOC Informational

Malicious NetSetupSvc.dll loaded into svchost.exe

A module tied to SolarStorm (TEARDROP NetSetupSvc.dll) was loaded from a malicious location into svchost.exe.

Module:
Platform Analytics
Agent event type:
Module
Category:
Dropper
Status:
Enabled
ATT&CK tactics: Execution (TA0002)
ATT&CK techniques: System Services (T1569)
Indicator:

Image Load module path = *\SysWOW64\NetSetupSvc.dll Process initiated by = svchost.exe , cgo name = svchost.exe , os parent name = svchost.exe Host host os = windows

Preventable: yes