This detection identifies potential legacy Borland C++ 1999 compiler artifacts or associated malware signatures within the environment using a specialized YARA rule. The SOC team should proactively hunt for these indicators to uncover dormant threats or unauthorized legacy software that may introduce vulnerabilities in the Azure Sentinel ecosystem.
rule FSGv110EngdulekxtBorlandC1999
{
meta:
author="malware-lu"
strings:
$a0 = { EB 02 CD 20 2B C8 68 80 [2] 00 EB 02 1E BB 5E EB 02 CD 20 68 B1 2B 6E 37 40 5B 0F B6 C9 }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 5 specific false positive scenarios for the FSGv110EngdulekxtBorlandC1999 detection rule, which targets legacy Borland C++ 1999 artifacts often found in older enterprise applications:
Legacy ERP Maintenance Scripts:
SYSTEM account.maintenance.exe, batch_job_erp) and the user context is NT AUTHORITY\SYSTEM. Alternatively, exclude file paths residing in dedicated legacy application directories like C:\Program Files\LegacyERP\Bin\.Antivirus Engine Scanning of Archived Data:
C:\Program Files\CrowdStrike\fs_qa.exe or MsMpEng.exe) when the child process matches the Borland signature. This ensures that scanning activities do not generate alerts for the scanned content itself.DevOps Build Pipeline Execution:
bcpp.exe or similar Bor