This detection identifies potential malicious activity involving the unpacking of specific beta versions of dynamic libraries or executables that may indicate early-stage fileless attacks or supply chain compromises within the Azure environment. A SOC team should proactively hunt for this behavior to uncover hidden threats that traditional signature-based tools might miss, ensuring rapid identification and containment of anomalies before they escalate into broader incidents.
rule Upackv038betaDwing
{
meta:
author="malware-lu"
strings:
$a0 = { BE B0 11 [2] AD 50 FF 76 34 EB 7C 48 01 [2] 0B 01 4C 6F 61 64 4C 69 62 72 61 72 79 41 00 00 18 10 00 00 10 00 00 00 00 [3] 00 00 [2] 00 10 00 00 00 02 00 00 04 00 00 00 00 00 38 00 04 00 00 00 00 00 00 00 00 [3] 00 02 00 00 00 00 00 00 }
$a1 = { BE B0 11 [2] AD 50 FF 76 34 EB 7C 48 01 [2] 0B 01 4C 6F 61 64 4C 69 62 72 61 72 79 41 00 00 18 10 00 00 10 00 00 00 00 [3] 00 00 [2] 00 10 00 00 00 02 00 00 04 00 00 00 00 00 38 00 04 00 00 00 00 00 00 00 00 [3] 00 02 00 00 00 00 00 00 ?? 00 00 ?? 00 00 ?? 00 00 [2] 00 00 00 10 00 00 10 00 00 00 00 00 00 0A 00 00 00 00 00 00 00 00 00 00 00 EE [3] 14 00 00 00 00 [6] 00 FF 76 38 AD 50 8B 3E BE F0 [3] 6A 27 59 F3 A5 FF 76 04 83 C8 FF 8B DF AB EB 1C 00 00 00 00 47 65 74 50 72 6F 63 41 64 64 72 65 73 73 00 00 [5] 00 00 00 40 AB 40 B1 04 F3 AB C1 E0 0A B5 ?? F3 AB 8B 7E 0C 57 51 E9 [4] E3 B1 04 D3 E0 03 E8 8D 53 18 33 C0 55 40 51 D3 E0 8B EA 91 FF 56 4C 33 D2 59 D1 E8 13 D2 E2 FA 5D 03 EA 45 59 89 6B 08 56 8B F7 2B F5 F3 A4 AC 5E B1 80 AA 3B 7E 34 0F 82 97 FE FF FF 58 5F 59 E3 1B 8A 07 47 04 18 3C 02 73 F7 8B 07 3C ?? 75 F1 B0 00 0F C8 03 46 38 2B C7 AB E2 E5 5E 5D 59 51 59 46 AD 85 C0 74 1F }
condition:
$a0 at pe.entry_point or $a1 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 2 string patterns in its detection logic.
Here are 5 specific false positive scenarios for the Upackv038betaDwing detection rule, along with suggested filters and exclusions:
Scenario: Automated Deployment via Microsoft Endpoint Configuration Manager (SCCM)
.msi or .zip) to endpoints. The Upackv038betaDwing rule often triggers when the SCCM client extracts these archives in the background using standard unpacking libraries that match the YARA signature’s heuristic for “suspicious unpacking behavior.”\Microsoft\CCM\ and the parent process is ccmexec.exe. Additionally, filter out events occurring between 02:00 and 04:00 local time on weekdays.Scenario: Antivirus Real-Time Scanning of Temporary Downloads
Downloads folder. The enterprise antivirus engine (e.g., CrowdStrike Falcon or Microsoft Defender for Endpoint) automatically unpacks these files in the %TEMP% directory before execution, triggering the rule due to the rapid creation of extracted child processes.C:\Users\*\Downloads\* and C:\Windows\Temp\*. Furthermore, exclude events where the parent process is a known AV engine (e.g., MsMpEng.exe, FalconSensor.exe) performing a scan rather than a user-initiated launch.Scenario: Scheduled PowerShell Script for Log Rotation