This detection identifies the execution of a specific stub engine associated with the FreeJoiner application, which may indicate legitimate software usage or the initial stage of a supply chain compromise involving this utility. Proactive hunting for this behavior in Azure Sentinel is essential to distinguish between expected administrative activity and potential adversary reconnaissance that leverages trusted applications to establish a foothold within the environment.
rule FreeJoiner153Stubengine17GlOFF
{
meta:
author="malware-lu"
strings:
$a0 = { E8 33 FD FF FF 50 E8 0D 00 00 00 CC FF 25 08 20 40 00 FF 25 0C 20 40 00 FF 25 10 20 40 00 FF 25 14 20 40 00 FF 25 18 20 40 00 FF 25 1C 20 40 00 FF 25 20 20 40 00 FF 25 24 20 40 00 FF 25 28 20 40 00 FF 25 00 20 40 00 }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 4 specific false positive scenarios for the FreeJoiner153Stubengine17GlOFF detection rule, tailored for a legitimate enterprise environment:
Scenario: Legitimate deployment of the “FreeJoiner” remote collaboration tool by the IT Helpdesk.
Stubengine process spawned during these silent installation phases as suspicious.ccmsetup.exe (SCCM) or Microsoft.Workplace.Joiner.exe, and the file path contains \Program Files\FreeJoiner\.Scenario: Scheduled antivirus heuristic scan triggering a stub engine.
Stubengine17 component activity./scan-mode=heuristic and restrict the alert if the process user context is NT SERVICE\AntivirusService.Scenario: Automated Group Policy Object (GPO) application of configuration settings.
Stubengine17) to apply these changes, which the YARA rule interprets as an anomalous execution chain.