This detection identifies the presence of Wise Installer stubs, which adversaries often leverage to stage and execute payloads during the initial phases of a compromise. Proactively hunting for these artifacts in Azure Sentinel allows the SOC team to uncover potential supply chain attacks or hidden installation activities that may indicate early-stage adversary movement before malicious execution occurs.
rule WiseInstallerStub
{
meta:
author="malware-lu"
strings:
$a0 = { 55 8B EC 81 EC 78 05 00 00 53 56 BE 04 01 00 00 57 8D 85 94 FD FF FF 56 33 DB 50 53 FF 15 34 20 40 00 8D 85 94 FD FF FF 56 50 8D 85 94 FD FF FF 50 FF 15 30 20 40 00 8B 3D 2C 20 40 00 53 53 6A 03 53 6A 01 8D 85 94 FD FF FF 68 00 00 00 80 50 FF D7 83 F8 FF }
$a1 = { 55 8B EC 81 EC ?? 04 00 00 53 56 57 6A [7] FF 15 [2] 40 00 [56] 80 ?? 20 }
$a2 = { 55 8B EC 81 EC [2] 00 00 53 56 57 6A 01 5E 6A 04 89 75 E8 FF 15 ?? 40 40 00 FF 15 ?? 40 40 00 8B F8 89 7D ?? 8A 07 3C 22 0F 85 ?? 00 00 00 8A 47 01 47 89 7D ?? 33 DB 3A C3 74 0D 3C 22 74 09 8A 47 01 47 89 7D ?? EB EF 80 3F 22 75 04 47 89 7D ?? 80 3F 20 }
condition:
$a0 at pe.entry_point or $a1 at pe.entry_point or $a2
}
This YARA rule can be deployed in the following contexts:
This rule contains 3 string patterns in its detection logic.
Here are 5 specific false positive scenarios for the WiseInstallerStub detection rule, including suggested filters and exclusions tailored for an enterprise environment:
Scenario: Microsoft Office Deployment Toolkit (ODT) Executions
setup.exe or performs a silent installation, it often spawns WiseInstallerStub.exe as part of the payload execution chain, triggering the YARA rule even though no malicious activity is present.Microsoft Office Setup.exe or odt.exe) and the specific file path: C:\Program Files\Microsoft Office\Office16\WiseInstallerStub.exe. Alternatively, filter alerts where the command line contains /quiet or /norestart flags typical of ODT deployments.Scenario: Scheduled Patch Deployment via SCCM/MECM
WiseInstallerStub.exe process is launched by the SCCM client service (ccmexec.exe) to handle the installation logic of third-party software updates, causing legitimate high-frequency alerts during patch cycles.ccmexec.exe and the execution occurs within a defined maintenance window (e.g., 02:00–06:00 UTC). Additionally, add an exclusion for file hashes belonging to known SCCM application packages stored in the distribution point.Scenario: Adobe Creative Cloud Updater Activity