This detection identifies potential malicious activity involving the specific IProtect library module (IProtect10Fxlib.dll) often associated with software protection mechanisms that may be leveraged by adversaries for process injection or DLL hijacking. A SOC team should proactively hunt for this behavior in Azure Sentinel to distinguish between legitimate application integrity checks and early-stage evasion techniques used by attackers to establish persistence within the environment.
rule IProtect10FxlibdllmodebyFuXdas
{
meta:
author="malware-lu"
strings:
$a0 = { EB 33 2E 46 55 58 4C 6F 61 64 4C 69 62 72 61 72 79 41 00 46 78 4C 69 62 2E 64 6C 6C 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [3] 00 60 E8 00 00 00 00 5D 81 ED 71 10 40 00 FF 74 24 20 E8 40 00 00 00 0B C0 74 2F 89 85 63 10 40 00 8D 85 3C 10 40 00 50 FF B5 63 10 40 00 E8 92 00 00 00 0B C0 74 13 89 85 5F 10 40 00 8D 85 49 10 40 00 50 FF 95 5F 10 40 00 8B 85 67 10 40 00 89 44 24 1C 61 FF E0 8B 7C 24 04 8D 85 00 10 40 00 50 64 FF 35 00 00 00 00 8D 85 53 10 40 00 89 20 89 68 04 8D 9D 0A 11 40 00 89 58 08 64 89 25 00 00 00 00 81 E7 00 00 FF FF 66 81 3F 4D 5A 75 0F 8B F7 03 76 3C 81 3E 50 45 00 00 75 02 EB 17 81 EF 00 00 01 00 81 FF 00 00 00 70 73 07 BF 00 00 F7 BF EB 02 EB D3 97 64 8F 05 00 00 00 00 83 C4 04 C2 04 00 8D 85 00 10 40 00 50 64 FF 35 00 00 00 00 8D 85 53 10 40 00 89 20 89 68 04 8D 9D 0A 11 40 00 89 58 08 64 89 25 00 00 00 00 8B 74 24 0C 66 81 3E 4D 5A 74 05 E9 8A 00 00 00 03 76 3C 81 3E 50 45 00 00 74 02 EB 7D 8B 7C 24 10 B9 96 00 00 00 32 C0 F2 AE 8B CF 2B 4C 24 10 8B 56 78 03 54 24 0C 8B 5A 20 03 5C 24 0C 33 C0 8B 3B 03 7C 24 0C 8B 74 24 10 51 F3 A6 75 05 83 C4 04 EB 0A 59 83 C3 04 40 3B 42 18 75 E2 3B 42 18 75 02 EB 35 8B 72 24 03 74 24 0C 52 BB 02 00 00 00 33 D2 F7 E3 5A 03 C6 33 C9 66 8B 08 8B 7A 1C 33 D2 BB 04 00 00 00 8B C1 F7 E3 03 44 24 0C 03 C7 8B 00 03 44 24 0C EB 02 33 C0 64 8F 05 00 00 00 00 83 C4 04 C2 08 00 E8 FA FD FF FF }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 4 specific false positive scenarios for the IProtect10FxlibdllmodebyFuXdas detection rule, along with recommended filters and exclusions:
Scenario: Microsoft Defender Antivirus Engine Updates
IProtect10 library is frequently invoked by the Windows Security service (Sense.exe) or the Microsoft Defender Antivirus engine when it performs background signature updates. In enterprise environments, these updates often run via scheduled tasks (e.g., “Microsoft Defender Antivirus Update”) during off-hours, triggering the YARA rule as a new DLL mode change occurs.Sense.exe or MsMpEng.exe. Additionally, filter out events occurring between 02:00 and 04:00 UTC if these align with your organization’s update window.Scenario: Endpoint Detection and Response (EDR) Scans
IProtect10 library to perform real-time file integrity monitoring or behavioral analysis. When these agents scan system directories, they may load this specific DLL mode, causing a legitimate trigger that mimics suspicious activity.FalconSensor.exe, S1Agent.exe, and cbpsservice.exe. You can also add a path-based exclusion for the installation directories of these tools (e.g., C:\Program Files\CrowdStrike\...).Scenario: Office 365 Click-to-Run Installation & Maintenance