This detection identifies potential malicious activity involving the unpacking of specific alpha-stage Dwing artifacts, which often serve as indicators for early-stage fileless or obfuscated threats. Proactively hunting for this behavior in Azure Sentinel allows the SOC team to uncover stealthy adversary movements that may evade standard signature-based defenses before they escalate into critical incidents.
rule Upackv036alphaDwing
{
meta:
author="malware-lu"
strings:
$a0 = { AB E2 E5 5D 59 8B 76 68 51 59 46 AD 85 C0 }
condition:
$a0
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 4 specific false positive scenarios for the Upackv036alphaDwing detection rule, including suggested filters and exclusions:
Scenario: Automated Software Deployment via SCCM/Intune
.zip, .7z) containing nested archives during scheduled maintenance windows. The YARA rule may flag the extraction process of these legitimate deployment payloads as suspicious “unpacking” behavior associated with the Dwing malware family.CCMExec.exe (SCCM) or Microsoft.IntuneManagementAgent service accounts. Specifically, exclude file paths containing \Windows\CCM\ or \Program Files\Microsoft Intune Agent\.Scenario: Enterprise Antivirus Real-Time Scanning
Upackv036alphaDwing signature due to the specific byte patterns of the extraction routine.csfalcon.exe, SentinelOneAgent.exe). Filter out alerts where the file extension being processed is .zip or .cab and the user context is a standard domain user rather than an interactive admin session.Scenario: Scheduled Backup and Archiving Jobs