← Back to SOC feed Coverage →

Certificate used for digitally signing malware.

yara LOW ReversingLabs
malware-family
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at ReversingLabs →
Retrieved: 2026-08-29T11:00:00Z · Confidence: medium

Hunt Hypothesis

This rule detects adversaries leveraging valid digital certificates to sign malicious executables, a tactic designed to bypass signature-based defenses and evade initial detection by impersonating trusted software. Proactive hunting in Azure Sentinel is essential because attackers increasingly abuse legitimate certificate infrastructure to establish persistence and execute stealthy attacks that traditional security controls may overlook due to the low severity of signed artifacts.

YARA Rule

rule cert_blocklist_049ce8c47f1f0e650cb086f0cfa7ca53 {
    meta:
        author      = "ReversingLabs"
        source      = "ReversingLabs"
        status      = "RELEASED"
        sharing     = "TLP:WHITE"
        category    = "INFO"
        description = "Certificate used for digitally signing malware."

    condition:
        uint16(0) == 0x5A4D and
        for any i in (0..pe.number_of_signatures): (
            pe.signatures[i].subject contains "Select'Assistance Pro" and
            pe.signatures[i].serial == "04:9c:e8:c4:7f:1f:0e:65:0c:b0:86:f0:cf:a7:ca:53" and
            1393804799 <= pe.signatures[i].not_after
        )
}

Deployment Notes

This YARA rule can be deployed in the following contexts:

False Positive Guidance

Here are 5 specific false positive scenarios for the rule “Certificate used for digitally signing malware,” including suggested filters and exclusions tailored for an enterprise environment:

Original source: https://github.com/reversinglabs/reversinglabs-yara-rules/blob/main/yara/certificate/blocklist.yara