This YARA rule targets specific unpacking or obfuscation patterns often associated with low-severity malware variants, indicating potential attempts to hide malicious code from static analysis. Proactively hunting for these signatures allows the SOC team to identify stealthy payloads that may be evading traditional detection methods before they can establish a foothold in the environment.
rule Upack024027beta028alphaDwing
{
meta:
author="malware-lu"
strings:
$a0 = { BE 88 01 40 00 AD 8B F8 95 AD 91 F3 A5 AD B5 ?? F3 AB AD 50 97 51 58 8D 54 85 5C FF 16 72 57 2C 03 73 02 B0 00 3C 07 72 02 2C 03 50 0F B6 5F FF C1 E3 ?? B3 00 8D 1C 5B 8D 9C 9D 0C 10 00 00 B0 }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Dwing (Dynamic Window) cache or associated memory structures during the initialization of the new detection modules.
CldFltMon.exe, FalconSensor.exe, SentinelOneAgent.exe) and the file path resides in the vendor’s specific installation directory (e.g., C:\Program Files\CrowdStrike\).chrome_crashpad_handler.exe, msedgewebview2.exe) might trigger the rule if they contain specific binary patterns associated with the Dwing structure.
chrome.exe, msedge.exe, firefox.exe and their child processes) and the image path is within the browser’s standard installation directory (e.g., C:\Program Files (x86)\Google\Chrome\).Dwing.