This hypothesis targets the presence of the nBinder v361 malware variant, a known tool used for process injection and code execution that often serves as an initial foothold for lateral movement. Proactively hunting for this signature in Azure Sentinel allows the SOC team to identify compromised endpoints before the adversary can establish persistence or escalate privileges, reducing the overall dwell time of the threat.
rule nBinderv361
{
meta:
author="malware-lu"
strings:
$a0 = { 6E 35 36 34 35 36 35 33 32 33 34 35 34 33 5F 6E 62 33 5C 00 5C 6E 35 36 34 35 36 35 33 32 33 34 35 34 33 5F 6E 62 33 5C }
condition:
$a0
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
nbind command-line utility (part of the nbind package) to generate native bindings for a Node.js project during a CI/CD pipeline or local build step.
node.exe or npm.exe, or where the command line contains arguments like --build, --install, or specific module names (e.g., nbind --build).nbind to recompile native dependencies after a system update or dependency change.
svc-build, app-pool) or where the parent process is svchost.exe (indicating a service) or cmd.exe/powershell.exe launched by a scheduled task ID associated with build/maintenance jobs.nbind internally to compile C++/C# interop layers during the initial installation phase on a user’s workstation.
setup.exe, install.exe, msiexec.exe) or where the working directory is under a standard installation path (e.g., C:\Program Files\, C:\Users\<user>\AppData\Local\Temp\).nbind in a controlled test environment or during a post-patch validation.