This detection identifies potential adversary activity involving Microsoft Visual C++ 2005 runtime components that may indicate early-stage execution of legitimate or malicious binaries within the Azure Sentinel environment. Proactively hunting for this behavior allows the SOC team to distinguish between standard development tool usage and anomalous runtime executions that could serve as a precursor to more complex attack chains, ensuring timely visibility into low-severity but foundational threat indicators.
rule FSGv110EngdulekxtMicrosoftVisualC6070ASM
{
meta:
author="malware-lu"
strings:
$a0 = { E8 01 00 00 00 5A 5E E8 02 00 00 00 BA DD 5E 03 F2 EB 01 64 BB 80 [2] 00 8B FA EB 01 A8 }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 5 specific false positive scenarios for the FSGv110EngdulekxtMicrosoftVisualC6070ASM rule, which targets Microsoft Visual C++ runtime components often associated with legitimate build and deployment activities:
Scenario: Automated CI/CD Pipeline Execution
msbuild.exe or vcpkg to compile applications, which inherently loads the Microsoft Visual C++ 6.0 (or legacy) runtime libraries during the linking phase.NT SERVICE\BuildAgent) and restrict detection to non-build server hosts. Alternatively, add a YARA condition to exclude execution paths containing \AzureDevOps\_builds\ or \github-runner\_work\.Scenario: Scheduled Antivirus Definition Updates
MpCmdG.exe, Rtvscan64.exe) download and install new definition signatures. This triggers the ASM logic as part of the update verification chain.MsMpEng.exe (Defender) or Symantec Endpoint Protection Client, specifically during the known maintenance window hours (e.g., 02:00–04:00 local time).Scenario: Legacy Application Deployment via SCCM