OpenSUpdater – Suspicious DLL Loading from SFX Process

This rule detects DLL files being loaded by common archive extraction and setup utilities (7-zip, setup.exe). Adversaries often use self-extracting (SFX) archives or installer wrappers to execute malicious code by placing a malicious DLL in the same directory as the executable to facilitate DLL side-loading or masquerading.