BIOC
Informational
✕
Malicious NetSetupSvc.dll loaded into svchost.exe
A module tied to SolarStorm (TEARDROP NetSetupSvc.dll) was loaded from a malicious location into svchost.exe.
- Module:
- Platform Analytics
- Agent event type:
- Module
- Category:
- Dropper
- Status:
- Enabled
ATT&CK tactics: Execution (TA0002)
ATT&CK techniques: System Services (T1569)
Indicator:
Image Load module path = *\SysWOW64\NetSetupSvc.dll Process initiated by = svchost.exe , cgo name = svchost.exe , os parent name = svchost.exe Host host os = windows
Preventable: yes