One way to spot a malicious proxy DLL when there are over 20 DLLs in the folder and one of them is lying, under 60 seconds. Let's go ๐
1/ An unsigned DLL named like a Microsoft runtime (๐๐๐๐๐๐๐ท๐บ๐ถ.๐๐๐)? Open it in your favorite disassembler. Exports look normal. Now double-click any export, and you see:
๐๐๐ ๐๐๐ก, ๐๐:๐๐๐๐๐๐๐
๐๐๐ ๐๐ ๐๐๐ ๐๐๐ [๐๐๐ก+๐พ๐ธ๐ถ๐]
Click another one, and it's the same thing. You see 291 exports but zero real code - every function is a forwarding address.
2/ Now check that table: ๐๐๐๐๐๐๐ in the .๐๐๐๐ section - it's zeroed on disk. Every export jumps through it, and the file has nothing in it. It stays empty until the DLL loads, then one function does ๐ป๐๐๐๐ป๐๐๐๐๐๐ข("๐๐๐๐๐๐๐ท๐บ๐ถ๐.๐๐๐") + ๐ถ๐๐๐ฟ๐๐๐๐ฐ๐๐๐๐๐๐ a few hundred times.
And there it is: ๐๐๐๐๐๐๐ท๐บ๐ถ๐.๐๐๐ - the legitimate DLL in the same folder with one extra letter in the name. The fake DLL carries the real one's name and forwards every call to it.
The 60-second checklist:
โ๏ธ DLL named like a Microsoft runtime (๐๐๐๐๐๐๐ท๐บ๐ถ.๐๐๐), but wait, Microsoft didn't sign it
โ๏ธ all exports share one identical code stub
โ๏ธ jump table zeroed on disk
โ๏ธ a second DLL with the same name + one extra letter