This detection identifies potential low-severity anomalies associated with the “FreeJoinerSmallbuild029GlOFF” signature, which may indicate early-stage reconnaissance or benign build artifacts mimicking adversary activity within the Azure Sentinel environment. A proactive hunt is warranted to validate whether these occurrences represent false positives from legitimate CI/CD processes or subtle indicators of a stealthy threat actor leveraging custom tooling for initial foothold establishment.
rule FreeJoinerSmallbuild029GlOFF
{
meta:
author="malware-lu"
strings:
$a0 = { 50 32 C4 8A C3 58 E8 DE FD FF FF 6A 00 E8 0D 00 00 00 CC FF 25 78 10 40 00 FF 25 7C 10 40 00 FF 25 80 10 40 00 FF 25 84 10 40 00 FF 25 88 10 40 00 FF 25 8C 10 40 00 FF 25 90 10 40 00 FF 25 94 10 40 00 FF 25 98 10 40 00 FF 25 9C 10 40 00 FF 25 A0 10 40 00 FF 25 A4 10 40 00 FF 25 AC 10 40 00 }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 4 specific false positive scenarios for the FreeJoinerSmallbuild029GlOFF detection rule, including suggested filters and exclusions:
Scenario: Scheduled Deployment of Internal Collaboration Tools
FreeJoiner client update to all workstations. This process installs or updates the SmallBuild029 component, triggering the YARA signature during the installation phase.ccmsetup.exe (SCCM) and wuauserv.exe (Windows Update Agent). Additionally, exclude file paths matching C:\Program Files\Microsoft Configuration Manager\AdminConsole\....Scenario: Automated CI/CD Pipeline Artifact Execution
java.exe (Jenkins) or gitlab-runner.exe. Add a file path exclusion for directories under C:\BuildAgents\builds\FreeJoiner\artifacts\.Scenario: Endpoint Protection Policy Enforcement