SynkLoader PhishLocker fake lock-screen overlay creation
Detects the execution of the PhishLocker module, a component of the SynkLoader malware. This module is designed to display a fake, full-screen Windows lock-screen overlay to conduct credential phishing. The rule identifies processes exhibiting the 'Main Window' title associated with these malicious DLLs (msvcp150.dll or msvcp160.dll) that are typically used for sideloading.
Microsoft Sentinel (KQL)

