This rule detects the presence of Nullsoft Install System (NSIS) executables, which are commonly used by adversaries to package and deploy malicious payloads or installers during initial access or lateral movement. Proactively hunting for these artifacts in Azure Sentinel helps identify potential unauthorized software installations or staging activities that may indicate an adversary is establishing a foothold or executing custom scripts within the environment.
rule NullsoftInstallSystemv1xx
{
meta:
author="malware-lu"
strings:
$a0 = { 55 8B EC 83 EC 2C 53 56 33 F6 57 56 89 75 DC 89 75 F4 BB A4 9E 40 00 FF 15 60 70 40 00 BF C0 B2 40 00 68 04 01 00 00 57 50 A3 AC B2 40 00 FF 15 4C 70 40 00 56 56 6A 03 56 6A 01 68 00 00 00 80 57 FF 15 9C 70 40 00 8B F8 83 FF FF 89 7D EC 0F 84 C3 00 00 00 }
$a1 = { 83 EC 0C 53 56 57 FF 15 20 71 40 00 05 E8 03 00 00 BE 60 FD 41 00 89 44 24 10 B3 20 FF 15 28 70 40 00 68 00 04 00 00 FF 15 28 71 40 00 50 56 FF 15 08 71 40 00 80 3D 60 FD 41 00 22 75 08 80 C3 02 BE 61 FD 41 00 8A 06 8B 3D F0 71 40 00 84 C0 74 0F 3A C3 74 }
condition:
$a0 at pe.entry_point or $a1 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 2 string patterns in its detection logic.
Uninstall.exe or Uninstall.exe wrapper during software deployment via Group Policy Preferences (GPP) or SCCM/MECM task sequences.
cmd.exe, powershell.exe, or wmiadap.exe (WMI) and the image path contains \Uninstall.exe or \Uninstall\Uninstall.exe.\\fileserver\apps\oldapp\setup.exe) to update or remove a Nullsoft-based application.
Z:\, U:\) or contains a known file server share name, and the parent process is explorer.exe or cmd.exe initiated by a user in the Domain Admins or App Support group.trial_app\uninstall.exe) to remove residual files after a test period.
schtasks.exe or TaskScheduler service, and the image path contains keywords like trial, temp, or cleanup in the directory name.C:\dev\projects\app\installer\uninstall.exe) to test build artifacts.
dev, qa, test, `