• CommunityEnterprisePlans
  • Intel Exchange
    Intel ExchangeDetections
  • Resources
  • About
  • Leaderboard
Join CommunitySign In
    All Detections

    ProRAM Implant DLL Sideloaded via Signed 360 Utility

    avatar
    GlassDiceBearhttps://www.dicebear.comhttps://creativecommons.org/publicdomain/zero/1.0/„Glass” (https://www.dicebear.com) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)
    Arnold Chan@slaz
    •updated Sep 6, 2026•0•0•0

    Detects the loading of the ProRAM implant DLL (somkernl.dll) when initiated by known sideloading carriers such as 360speedld.exe or SoftupNotify.exe, which are signed utilities frequently abused for this purpose.

    YARA

    Tags

    T1574.001 - DLLTA0005 - StealthTA0002 - ExecutionFile Executable DetectedProcess Module LoadWindowsWindows Sysmon

    Found in

    • Funnull CDN Poisoning and Sub-Store Zero-Day CampaignLast updated Sep 7, 2026
    • Funnull CDN Poisoning and Sub-Store Zero-Day CampaignLast updated Sep 6, 2026
    • Funnull CDN Poisoning and Sub-Store Zero-Day CampaignLast updated Sep 6, 2026
    • Funnull CDN Poisoning and Sub-Store Zero-Day CampaignLast updated Sep 6, 2026

    Community Inspired.
    AI Enhanced.
    Better Detections.

    Follow Us

    Company

    • About
    • Leaderboard

    Product

    • Community
    • Enterprise
    • Plans

    © 2026 Copyright. All Rights Reserved.

    Privacy PolicyTerms of Service

    Sign up to view this detection

    or

    Already have an account?