This hunt targets adversaries leveraging legacy code artifacts common to both the WannaCry ransomware and the Lazarus Group’s early backdoors, suggesting a potential convergence of attack methodologies or supply chain reuse. Proactively hunting for these shared signatures in Azure Sentinel is critical to identify dormant threats that may be utilizing established, trusted code patterns to evade standard detection while preparing for multi-stage campaigns.
rule lazaruswannacry {
meta:
description = "Rule based on shared code between Feb 2017 Wannacry sample and Lazarus backdoor from Feb 2015 discovered by Neel Mehta"
date = "2017-05-15"
reference = "https://twitter.com/neelmehta/status/864164081116225536"
author = "Costin G. Raiu, Kaspersky Lab"
version = "1.0"
hash = "9c7c7149387a1c79679a87dd1ba755bc"
hash = "ac21c8ad899727137c4b94458d7aa8d8"
strings:
$a1 = { 51 53 55 8B 6C 24 10 56 57 6A 20 8B 45 00 8D 75 04 24 01 0C 01 46 89 45 00 C6 46 FF 03 C6 06 01 46 56 E8 }
$a2 = { 03 00 04 00 05 00 06 00 08 00 09 00 0A 00 0D 00 10 00 11 00 12 00 13 00 14 00 15 00 16 00 2F 00 30 00 31 00 32 00 33 00 34 00 35 00 36 00 37 00 38 00 39 00 3C 00 3D 00 3E 00 3F 00 40 00 41 00 44 00 45 00 46 00 62 00 63 00 64 00 66 00 67 00 68 00 69 00 6A 00 6B 00 84 00 87 00 88 00 96 00 FF 00 01 C0 02 C0 03 C0 04 C0 05 C0 06 C0 07 C0 08 C0 09 C0 0A C0 0B C0 0C C0 0D C0 0E C0 0F C0 10 C0 11 C0 12 C0 13 C0 14 C0 23 C0 24 C0 27 C0 2B C0 2C C0 FF FE }
condition:
uint16(0) == 0x5A4D and filesize < 15000000 and all of them
}
This YARA rule can be deployed in the following contexts:
This rule contains 2 string patterns in its detection logic.
Here are specific false positive scenarios for the detection rule based on shared code between the February 2017 WannaCry sample and the February 2015 Lazarus backdoor:
Antivirus Definition Updates via Windows Update
MsMpEng.exe (Microsoft Defender) or specific vendor agents (e.g., CsSvc.exe, Symantec Endpoint Protection) when the parent process is Wuauserv.exe or Windows Update.Enterprise Patch Management Deployment
ccmexec.exe (SCCM) or Ansible Runner, specifically filtering events where the file path contains \Windows\SoftwareDistribution\Download or the deployment package ID matches the organization’s standard patching schedule.Legacy Application Maintenance and Backup Jobs