Suspicious Ping Loopback Delay Followed by File Deletion for Evasion

PremiumReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-09-21
Updated
2026-09-21

ATT&CK techniques

Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

  14. Impact

What it detects

This rule detects a cmd chain that pings the loopback address with a repeat count to sleep and then deletes a file, the self cleanup and timing evasion used in the Blind Eagle campaign. Using ping as a sleep before deleting the dropper stalls sandboxes and removes artifacts after execution.

Related detections9 linkedT1070.004 — drag to rearrange
Suspicious Alternate Data Stream Self-Deletion via process_creation
Suspicious Crontab Removal via Command Line (via process_creation)
Suspicious Self-Deletion via Ping Loopback and Del (via process_creation)
Malicious Self-Deletion Via Fsutil SetZeroData
Self-Deletion via Ping Loopback Delay and Del Command
Suspicious Deletion of Explorer RunMRU Values
Suspicious PowerShell Self-Delete Of Executable via Process Creation
Suspicious Prefetch Deletion for Anti-Forensics
Malicious Ransomware Self-Deletion via Ping Loopback and Del
Suspicious Ping Loopback Delay Followed by File Deletion for Evasion
Pivot detection · T1070.004 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.