This hypothesis targets the execution of Nullsoft Install System (NSIS) installers, which adversaries frequently leverage to deploy payloads or establish persistence through standard Windows installation mechanisms. Proactively hunting for these artifacts in Azure Sentinel helps identify potentially unauthorized software deployments or staging activities that may indicate initial access or lateral movement within the environment.
rule NullsoftInstallSystemv20b4
{
meta:
author="malware-lu"
strings:
$a0 = { 83 EC 10 53 55 56 57 C7 44 24 14 F0 91 40 00 33 ED C6 44 24 13 20 FF 15 2C 70 40 00 55 FF 15 88 72 40 00 BE 00 D4 42 00 BF 00 04 00 00 56 57 A3 60 6F 42 00 FF 15 C4 70 40 00 E8 9F FF FF FF 8B 1D 90 70 40 00 85 C0 75 21 68 FB 03 00 00 56 FF 15 60 71 40 00 }
$a1 = { 83 EC 14 83 64 24 04 00 53 55 56 57 C6 44 24 13 20 FF 15 30 70 40 00 BE 00 20 7A 00 BD 00 04 00 00 56 55 FF 15 C4 70 40 00 56 E8 7D 2B 00 00 8B 1D 8C 70 40 00 6A 00 56 FF D3 BF 80 92 79 00 56 57 E8 15 26 00 00 85 C0 75 38 68 F8 91 40 00 55 56 FF 15 60 71 }
condition:
$a0 or $a1
}
This YARA rule can be deployed in the following contexts:
This rule contains 2 string patterns in its detection logic.
unins000.exe uninstaller during a routine software patching cycle or end-of-life decommissioning of applications (e.g., removing Adobe Creative Cloud, Java, or Visual Studio components).
msiexec.exe, setup.exe, uninst.exe) or where the command line contains arguments like /S (silent), /U (uninstall), or specific product GUIDs. Additionally, exclude files located in standard application directories like C:\Program Files\ or C:\Program Files (x86)\ that match known vendor paths.CCMExec.exe for SCCM, IntuneAgent.exe, or PDQDeploy.exe) or where the process is launched from a network share or specific deployment staging directory (e.g., \\fileserver\deploy\).svchost.exe with specific arguments) or known internal service executables. You can also filter by checking if the executable path resides in a controlled internal software repository directory (e.g., C:\InternalTools\ or D:\SharedApps\).