This hunt detects the execution of InnoSetup installer modules (version 129), which adversaries often leverage to deliver custom payloads or obfuscate initial installation stages during software deployment. A SOC team should proactively hunt for this behavior in Azure Sentinel to identify potential supply chain compromises or living-off-the-land tactics where attackers utilize legitimate installers to establish a foothold before deploying malicious components.
rule InnoSetupModulev129
{
meta:
author="malware-lu"
strings:
$a0 = { 55 8B EC 83 C4 C0 53 56 57 33 C0 89 45 F0 89 45 EC 89 45 C0 E8 5B 73 FF FF E8 D6 87 FF FF E8 C5 A9 FF FF E8 E0 }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 5 specific false positive scenarios for the InnoSetupModulev129 detection rule, including suggested filters and exclusions:
Scenario: Deployment of Internal Line-of-Business Applications via SCCM
setup.exe) to trigger the rule upon execution during business hours.ProcessName contains ccmexec.exe or smsengine.exe (SCCM agents) AND the AccountName belongs to the IT-Deployments service account group.Scenario: Scheduled Patching Job for Third-Party Security Tools
InnoSetupModulev129 binary used by the vendor to the allowlist and restrict alerts to only fire outside of the 01:00–04:00 maintenance window for this specific process.Scenario: Software Installation via Group Policy (GPO) Startup Scripts