This detection identifies the execution of Inno Setup installer modules (version 109a), which adversaries frequently leverage to deliver legitimate-looking payloads that may conceal malicious components or facilitate initial access. Proactive hunting for this behavior in Azure Sentinel is essential to distinguish between routine software deployments and potential supply chain attacks where attackers abuse trusted installers to establish a foothold within the environment.
rule InnoSetupModulev109a
{
meta:
author="malware-lu"
strings:
$a0 = { 55 8B EC 83 C4 C0 53 56 57 33 C0 89 45 F0 89 45 C4 89 45 C0 E8 A7 7F FF FF E8 FA 92 FF FF E8 F1 B3 FF FF 33 C0 }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 5 specific false positive scenarios for the InnoSetupModulev109a detection rule, including recommended filters and exclusions:
Scenario: Automated Deployment of Internal Line-of-Business (LOB) Applications via SCCM
ccmexec.exe) acting as the parent process, specifically when launching executables with filenames matching *.exe located in the C:\Program Files\InternalApps\ directory. Additionally, add an exception for the specific Inno Setup version hash if it is consistent across deployments.Scenario: Scheduled Patching of Third-Party Utilities (e.g., Adobe Acrobat or Zoom)
msiexec or direct executable launches the setup engine.Task Scheduler (taskschd.exe) and the file path contains known vendor directories (e.g., C:\Program Files\Adobe, C:\Program Files\Zoom). Alternatively, filter by the specific SHA-256 hash of the trusted Inno Setup module version used by these vendors.Scenario: Onboarding Scripts Executing via Group Policy Preferences