This detection identifies specific file artifacts matching the “Morphinev27Holy FatherRatter29A” signature, which may indicate early-stage malware or benign software activity within the environment. Proactively hunting for this pattern in Azure Sentinel allows the SOC team to validate false positives and uncover potential low-severity threats that could serve as indicators of compromise before they escalate into critical incidents.
rule Morphinev27Holy_FatherRatter29A
{
meta:
author="malware-lu"
strings:
$a0 = { 00 00 00 00 6B 65 72 6E 65 6C 33 32 2E 64 6C 6C 00 00 47 65 74 50 72 6F 63 41 64 64 72 65 73 73 00 00 4C 6F 61 64 4C 69 62 72 61 72 79 41 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 }
$a1 = { 00 00 00 00 00 00 00 00 [8] 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [8] 00 00 00 00 [8] 00 00 00 00 6B 65 72 6E 65 6C 33 32 2E 64 6C 6C 00 00 47 65 74 50 72 6F 63 }
condition:
$a0 or $a1
}
This YARA rule can be deployed in the following contexts:
This rule contains 2 string patterns in its detection logic.
Here are 4 specific false positive scenarios for the Morphinev27Holy FatherRatter29A detection rule, including suggested filters and exclusions tailored for an enterprise environment:
Scenario: Enterprise Antivirus Real-Time Scanning
ProcessName is MsMpEng.exe, Cfsensr64.exe, or csfalcon.exe running under the SYSTEM account. Add a rule condition to ignore alerts if the parent process is an AV service and the file path resides within C:\Program Files\Microsoft Defender\ or C:\ProgramData\CrowdStrike\.Scenario: Scheduled Backup and Patching Jobs
ProcessName matches backup agents like vrb.exe (Veeam) or usoc.dll (Windows Update). Alternatively, exclude file paths containing \Backup\, \WSUSContent\, or \Temp\Maintenance\.Scenario: Legacy Line-of-Business Application Updates