This rule identifies the presence of the “FucknJoyv10cUsAr” YARA signature, which likely indicates a specific memory-resident payload or custom malware variant executing within the environment. Proactively hunting for this indicator allows the SOC team to detect low-severity, potentially stealthy intrusions that may evade standard behavioral detections, ensuring early identification of targeted or niche threats in Azure Sentinel.
rule FucknJoyv10cUsAr
{
meta:
author="malware-lu"
strings:
$a0 = { 60 E8 00 00 00 00 5D 81 ED D8 05 40 00 FF 74 24 20 E8 8C 02 00 00 0B C0 0F 84 2C 01 00 00 89 85 6C 08 40 00 8D 85 2F 08 40 00 50 FF B5 6C 08 40 00 E8 EF 02 00 00 0B C0 0F 84 0C 01 00 00 89 85 3B 08 40 00 8D 85 3F 08 40 00 50 FF B5 6C 08 40 00 E8 CF 02 00 }
$a1 = { 60 E8 00 00 00 00 5D 81 ED D8 05 40 00 FF 74 24 20 E8 8C 02 00 00 0B C0 0F 84 2C 01 00 00 89 85 6C 08 40 00 8D 85 2F 08 40 00 50 FF B5 6C 08 40 00 E8 EF 02 00 00 0B C0 0F 84 0C 01 00 00 89 85 3B 08 40 00 8D 85 3F 08 40 00 50 FF B5 6C 08 40 00 E8 CF 02 00 00 0B C0 0F 84 EC 00 00 00 89 85 4D 08 40 00 8D 85 51 08 40 00 50 FF B5 6C 08 40 00 E8 AF 02 00 00 0B C0 0F 84 CC 00 00 00 89 85 5C 08 40 00 8D 85 67 07 40 00 E8 7B 02 00 00 8D B5 C4 07 40 00 56 6A 64 FF 95 74 07 40 00 46 80 3E 00 75 FA C7 06 74 6D 70 2E 83 C6 04 C7 06 65 78 65 00 8D 85 36 07 40 00 E8 4C 02 00 00 33 DB 53 53 6A 02 53 53 68 00 00 00 40 8D 85 C4 07 40 00 50 FF 95 74 07 40 00 89 85 78 07 40 00 8D 85 51 07 40 00 E8 21 02 00 00 6A 00 8D 85 7C 07 40 00 50 68 00 [2] 00 8D 85 F2 09 40 00 50 FF }
condition:
$a0 at pe.entry_point or $a1 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 2 string patterns in its detection logic.
Joy library for UI rendering or event handling, resulting in the string FucknJoy appearing in the class file or JAR archive.
.jar, .class, or .war located in standard application directories (e.g., C:\Program Files\InternalApps\, /opt/app/lib/) where the parent process is a known Java runtime (java.exe, jre/bin/java).Joy with a debug flag that prepends “Fuckn” to the output binary name for versioning clarity (e.g., FucknJoyv10cUsAr.dll).
C:\Users\<dev>\Projects\, /home/<dev>/work/) where the parent process is a build tool like msbuild.exe, dotnet.exe, npm, or make.FucknJoyv10cUsAr.tmp during a data aggregation phase, which is then deleted or moved to a log archive.
.tmp, .log, or .bak that are older than 15 minutes and located in temporary directories (%TEMP%, /tmp/) or application log folders (C:\Logs\, /var/log/app/).