← Back to SOC feed Coverage →

Certificate used for digitally signing Zeus malware.

yara LOW ReversingLabs
malware-family
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at ReversingLabs →
Retrieved: 2026-08-28T23:00:00Z · Confidence: medium

Hunt Hypothesis

This detection identifies the presence of digital certificates historically associated with signing the Zeus malware family, signaling potential supply chain compromise or legacy persistence mechanisms within the environment. A proactive hunt is essential in Azure Sentinel to validate whether these specific certificates are actively authenticating legitimate traffic or if they represent a stealthy adversary leveraging trusted identities to evade standard signature-based defenses.

YARA Rule

rule cert_blocklist_75a38507bf403b152125b8f5ce1b97ad {
    meta:
        author      = "ReversingLabs"
        source      = "ReversingLabs"
        status      = "RELEASED"
        sharing     = "TLP:WHITE"
        category    = "INFO"
        description = "Certificate used for digitally signing Zeus malware."

    condition:
        uint16(0) == 0x5A4D and
        for any i in (0..pe.number_of_signatures): (
            pe.signatures[i].subject contains "isonet ag" and
            pe.signatures[i].serial == "75:a3:85:07:bf:40:3b:15:21:25:b8:f5:ce:1b:97:ad" and
            1395359999 <= pe.signatures[i].not_after
        )
}

Deployment Notes

This YARA rule can be deployed in the following contexts:

False Positive Guidance

Here are 4 specific false positive scenarios and their corresponding filters/exclusions for the “Certificate used for digitally signing Zeus malware” detection rule:

Original source: https://github.com/reversinglabs/reversinglabs-yara-rules/blob/main/yara/certificate/blocklist.yara