This detection identifies the presence of the Klez worm malware, which is known for spreading via email attachments and exploiting network shares to establish persistence on endpoints. SOC teams should proactively hunt for this threat in Azure Sentinel because early identification allows for rapid containment before the worm can propagate laterally across the environment or exfiltrate sensitive data through its established command-and-control channels.
rule VIRUSIWormKLEZ
{
meta:
author="malware-lu"
strings:
$a0 = { 55 8B EC 6A FF 68 40 D2 40 ?? 68 04 AC 40 ?? 64 A1 [4] 50 64 89 25 [4] 83 EC 58 53 56 57 89 65 E8 FF 15 BC D0 }
condition:
$a0
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 4 specific false positive scenarios for the VIRUSIWormKLEZ detection rule in an enterprise environment, along with targeted filters and exclusions:
Scenario: Legacy Antivirus Engine Updates
C:\Program Files\Symantec or C:\ProgramData\McAfee. Additionally, create a time-based filter to suppress alerts during the defined maintenance window (e.g., 02:00–04:00 UTC) when these updates are known to occur.Scenario: System Administrator Script Execution
wscript.exe host with specific command-line arguments that match the YARA rule’s heuristic for KLEZ propagation, particularly when processing large batches of .docx or .xlsx files in shared network drives.powershell.exe and python.exe when launched by specific service accounts (e.g., DOMAIN\svc-admin-provisioning). Filter alerts where the parent process is taskeng.exe (Task Scheduler) and the command line contains keywords like “bulk” or “provision”.Scenario: Third-Party Backup Agent Operations