This detection identifies the presence of a specific legacy or potentially benign stub engine artifact (FreeJoiner153Stubengine171) that may indicate outdated software configurations or residual components from previous deployments within the Azure Sentinel environment. Proactive hunting for this signature is essential to distinguish between harmless legacy noise and potential indicators of compromise, ensuring that low-severity alerts do not obscure critical threats while maintaining an accurate inventory of active system components.
rule FreeJoiner153Stubengine171GlOFF
{
meta:
author="malware-lu"
strings:
$a0 = { E8 02 FD FF FF 6A 00 E8 0D 00 00 00 CC FF 25 80 10 40 00 FF 25 84 10 40 00 FF 25 88 10 40 00 FF 25 8C 10 40 00 FF 25 90 10 40 00 FF 25 94 10 40 00 FF 25 98 10 40 00 FF 25 9C 10 40 00 FF 25 A0 10 40 00 FF 25 A8 10 40 00 }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 4 specific false positive scenarios for the FreeJoiner153Stubengine171GlOFF detection rule, along with targeted filters and exclusions:
Scenario: Scheduled Office Add-in Deployment via Microsoft Endpoint Configuration Manager (MECM/SCCM)
Stubengine171) executing in the background to register COM components and update registry keys for Outlook integration.ccmsetup.exe or wuauserv.exe (Windows Update Agent) when it is the parent process of the detected artifact. Additionally, exclude file paths containing \Microsoft Endpoint Configuration Manager\.Scenario: Automated Group Policy Object (GPO) Application for Shared Meeting Rooms
OU=MeetingRooms. Alternatively, exclude execution paths starting with \System Volume Information\GroupPolicy\ or specific GPO script identifiers.Scenario: Endpoint Detection and Response (EDR) Self-Healing Routine