It looks like someone found a way to DLL side load with sqlwriter.exe using the exported set_se_translator function :D

https://www.zscaler.com/blogs/security-research/european-diplomats-targeted-spikedwine-wineloader

#security #dllsideloading #malware #wineloader #sqlwriter

European diplomats targeted by SPIKEDWINE with WINELOADER

A technical analysis of a new threat actor delivering WINELOADER malware in a phishing campaign targeting European diplomats

VSS / SQLWriter sequence of warnings and error (... subset of the volumes ...) – SQLServerCentral Forums

VSS / SQLWriter sequence of warnings and error (... subset of the volumes ...) Forum – Learn more on SQLServerCentral

SQLServerCentral