This detection identifies potential malware activity by leveraging a specialized YARA signature to pinpoint specific virus engine behaviors within the SoftEDV system environment. A proactive hunt is essential for Azure Sentinel users to validate these low-severity findings early, ensuring that subtle indicators of compromise are not overlooked before they escalate into broader incidents.
rule DrWebVirusFindingEngineInSoftEDVSysteme
{
meta:
author="malware-lu"
strings:
$a0 = { B8 01 00 00 00 C2 0C 00 8D 80 00 00 00 00 8B D2 8B ?? 24 04 }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 3-5 specific false positive scenarios for the DrWebVirusFindingEngineInSoftEDVSysteme detection rule, including suggested filters and exclusions:
Scenario: Scheduled Antivirus Full Scan Execution
C:\Program Files\Dr.Web Anti-virus\bin\ or specific scheduled task names like \Microsoft\Windows\TaskScheduler\DrWebFullScan.Scenario: Software Deployment via Endpoint Management Tools
ccmsetup.exe (SCCM) or IvantiAgent.exe. Additionally, filter out events occurring during known deployment windows defined in the Change Management system (e.g., Tuesday 10:00–14:00).Scenario: Automated Backup and Archiving Jobs