Adversaries create the 'Office Test\Special\Perf' registry key and specify a malicious DLL path that is auto-loaded when an Office application starts. This DLL is injected into the Office process memory space and can provide persistent execution without requiring macro enablement.
WinEventLog:Sysmon
EventCode=13, 14
WinEventLog:Sysmon
EventCode=1
WinEventLog:Sysmon
EventCode=7
WinEventLog:Sysmon
EventCode=11
WinEventLog:Microsoft-Office-Alerts
Unexpected DLL or component loaded at Office startup
[RegistryPath]
Path to 'Office test\Special\Perf' may vary by Office version, 32/64-bit, or architecture (HKCU vs HKLM)
[DLLPath]
Injected DLL may reside in different user-writable locations (e.g., %APPDATA%, %TEMP%, or network shares)
[OfficeProcessName]
Process name (e.g., winword.exe, excel.exe) may vary by Office deployment and usage
[TimeWindow]
Time between DLL registry creation and first Office execution may vary depending on user activity
[UserContext]
Malicious DLL may target only specific users, necessitating correlation with interactive logon sessions