This detection identifies potential stealthy file execution or process injection behaviors captured by the BlindSpot10s134k YARA signature within Azure Sentinel workloads. Although marked as low severity, proactive hunting for this indicator is essential to uncover early-stage adversary activity that may evade standard alerting thresholds and prevent lateral movement before escalation.
rule BlindSpot10s134k
{
meta:
author="malware-lu"
strings:
$a0 = { 55 8B EC 81 EC 50 02 00 00 8D 85 B0 FE FF FF 53 56 A3 90 12 40 00 57 8D 85 B0 FD FF FF 68 00 01 00 00 33 F6 50 56 FF 15 24 10 40 00 56 68 80 00 00 00 6A 03 56 56 8D 85 B0 FD FF FF 68 00 00 00 80 50 FF 15 20 10 40 00 56 56 68 00 08 00 00 50 89 45 FC FF 15 1C 10 40 00 8D 45 F8 8B 1D 18 10 40 00 56 50 6A 34 FF 35 90 12 40 00 FF 75 FC FF D3 85 C0 0F 84 7F 01 00 00 39 75 F8 0F 84 76 01 00 00 A1 90 12 40 00 66 8B 40 30 66 3D 01 00 75 14 8D 85 E4 FE FF FF 68 04 01 00 00 50 FF 15 14 10 40 00 EB 2C 66 3D 02 00 75 14 8D 85 E4 FE FF FF 50 68 04 01 00 00 FF 15 10 10 40 00 EB 12 8D 85 E4 FE FF FF 68 04 01 00 00 50 FF 15 0C 10 40 00 8B 3D 08 10 40 00 8D 85 E4 FE FF FF 68 54 10 40 00 50 }
condition:
$a0
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 5 specific false positive scenarios for the BlindSpot10s134k YARA rule, tailored to a legitimate enterprise environment:
Scenario: Scheduled Antivirus Database Updates
BlindSpot10s134k.MsMpEng.exe (Microsoft Defender) or Symantec Antivirus Console, and restrict the rule to trigger only when the file path contains \ProgramData\Microsoft\Antimalware\Scan\.Scenario: Automated Software Deployment via SCCM
.msi or .exe) to workstations. During the installation phase, the setup wizard extracts temporary binaries that mimic the behavior of the detection logic, causing a spike in alerts during business hours.ccmsetup.exe and msiexec.exe, specifically when the command line arguments contain /quiet or /install.Scenario: Cloud Backup Agent Operations
VeeamTransportService.exe or `rubrik-agent