Hello @Kayyum1978
If you are referring to:
https://www.microsoft.com/security/blog/2021/09/27/foggyweb-targeted-nobelium-malware-leads-to-persi...
There currently are no samples available for the IOCs mentioned in the article for a DAT detection.
Based on the article you may create a rule for initially report only on the creation of:
%WinDir%\ADFS\version.dll
%WinDir%\SystemResources\Windows.Data.TimeZones\pris\Windows.Data.TimeZones.zh-PH.pri
after confirmation that it doesn;t cause false positives in your environment you may set it to block.
At this moment this is all the information we have available.
Was my reply helpful?
If you find this post useful, Please give it a Kudos! Also, Please don't forget to select "Accept as a solution" if this reply resolves your query!
Thanks and regards,
Tiago A