This hunt hypothesis targets the execution of the specific “ANDpakk2018” malware signature identified by Dmitry Andreev to detect potential legacy or targeted threats within the environment. A proactive search in Azure Sentinel is recommended because this low-severity YARA rule may indicate early-stage reconnaissance or dormant activity that requires deeper investigation before it escalates into a critical incident.
rule ANDpakk2018byDmitryANDAndreev
{
meta:
author="malware-lu"
strings:
$a0 = { FC BE D4 00 40 00 BF 00 [2] 00 57 83 CD FF 33 C9 F9 EB 05 A4 02 DB 75 05 8A 1E 46 12 DB 72 F4 33 C0 40 02 DB 75 05 8A 1E 46 12 DB 13 C0 02 DB 75 05 8A 1E 46 12 DB 72 0E 48 02 DB 75 05 8A 1E 46 12 DB 13 C0 EB DC 83 E8 03 72 0F C1 E0 08 AC 83 F0 FF 74 4D D1 F8 8B E8 EB 09 02 DB 75 05 8A 1E 46 12 DB 13 C9 02 DB 75 05 8A 1E 46 12 DB 13 C9 75 1A 41 02 DB 75 05 8A 1E 46 12 DB 13 C9 02 DB 75 05 8A 1E 46 12 DB 73 EA 83 C1 02 81 FD 00 FB FF FF 83 D1 01 56 8D 34 2F F3 A4 5E E9 73 FF FF FF C3 }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 3-5 specific false positive scenarios for the ANDpakk2018byDmitryANDAndreev YARA rule, tailored for an enterprise environment:
Scenario: The rule triggers on a legitimate software installer executed by the Microsoft Endpoint Configuration Manager (SCCM) during a scheduled deployment window.
ccmsetup.exe and restrict detection to business hours (08:00–18:00) for the specific file path pattern C:\Windows\CCM\Logs\*.Scenario: A scheduled backup job initiated by Veeam Backup & Replication generates a temporary archive file that matches the rule’s signature.
ANDpakk logic, often resulting in high false positive rates during nightly backup cycles.Veeam.Backup.Service.exe and the file extension matches .vbk or .log, specifically within the directory tree C:\ProgramData\Veeam\Backup\.Scenario: An automated security scan performed by CrowdStrike Falcon (or similar EDR) generates a quarantine artifact that triggers the rule.
ANDpakk detection logic, mistaking the security tool’s own output for a potential threat.