This detection identifies the execution of UPack v0.11 Dwing, a known unpacking utility often leveraged by adversaries to conceal malicious payloads within compressed archives during initial infection phases. Proactive hunting for this behavior in Azure Sentinel is essential to uncover stealthy delivery mechanisms that may bypass standard signature-based defenses and reveal early-stage command-and-control activities.
rule UPackv011Dwing
{
meta:
author="malware-lu"
strings:
$a0 = { BE 48 01 40 00 AD 8B F8 95 A5 33 C0 33 C9 AB 48 AB F7 D8 B1 04 F3 AB C1 E0 0A B5 1C F3 AB AD 50 97 51 AD 87 F5 58 8D 54 86 5C FF D5 72 5A 2C 03 73 02 B0 00 3C 07 72 02 2C 03 50 0F B6 5F FF C1 E3 03 B3 00 8D 1C 5B 8D 9C 9E 0C 10 00 00 B0 01 67 E3 29 8B D7 }
condition:
$a0
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 5 specific false positive scenarios for the UPackv011Dwing detection rule, including suggested filters and exclusions:
Scenario: Legitimate deployment of software updates via Microsoft Endpoint Configuration Manager (SCCM) or Intune.
UPack executable extracts compressed payloads on endpoints, triggering the YARA rule.ccmsetup.exe (SCCM) or Microsoft.Workplace.Join.exe (Intune), and the file path resides within the standard software distribution folders (e.g., C:\Windows\CCM\Cache).Scenario: Execution of scheduled antivirus definition updates by CrowdStrike Falcon or Symantec Endpoint Protection.
\Program Files\CrowdStrike\ or \Symantec Endpoint Protection\, specifically filtering out processes named Cfservice.exe or Rtvscan64.exe when they are performing update operations.Scenario: Automated backup and archival tasks using Veeam Backup & Replication agents.
System or a dedicated service account.