This detection identifies the presence of the Ningishzida10CyberDoom malware family on endpoints by leveraging specific YARA signatures to catch known malicious artifacts. Proactive hunting for this threat in Azure Sentinel is essential to validate its initial low-severity classification and uncover potential lateral movement or data exfiltration activities that may not trigger immediate high-priority alerts.
rule Ningishzida10CyberDoom
{
meta:
author="malware-lu"
strings:
$a0 = { 9C 60 96 E8 00 00 00 00 5D 81 ED 03 25 40 00 B9 04 1B 00 00 8D BD 4B 25 40 00 8B F7 AC [48] AA E2 CC }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 5 specific false positive scenarios for the Ningishzida10CyberDoom detection rule, including suggested filters and exclusions:
Scenario: Legitimate deployment of Microsoft Defender Antivirus updates via Windows Update Agent.
WindowsUpdate.exe or usocdworker.exe process frequently spawns child processes in the %ProgramData%\Microsoft\Windows Defender directory that match the YARA signature’s file structure patterns, triggering an alert during daily patch cycles (e.g., Tuesday mornings).usocdworker.exe or wuauserv.exe and the file path contains \Microsoft\Windows Defender\.Scenario: Scheduled backup jobs executed by Veeam Backup & Replication.
Veeam.Backup.Service.exe) creates temporary staging files in the C:\ProgramData\Veeam\Backup directory. These files often contain embedded signatures or headers that mimic the specific byte patterns detected by the Ningishzida rule, causing high-volume alerts during the 02:00–04:00 maintenance window.Veeam.Backup.Service.exe and the file extension is .vbk or .log, specifically within the Veeam installation directory.Scenario: Automated software distribution via Microsoft Endpoint Configuration Manager (SCCM).
ccmexec.exe) pushes new applications to endpoints, it extracts installer packages into the C:\Windows\CCMCache folder. The extraction process generates temporary executables and scripts that align with the YARA logic for “suspicious executable behavior,” leading to false positives