PhishLocker Fake Lock Screen DLL Activity via pythonw.exe
Detects anomalous behavior by pythonw.exe where it interacts with screen locker assets or loads specific DLLs from non-standard locations, indicative of a PhishLocker-style fake lock screen being deployed to capture user credentials.
Sigma

