This detection identifies potential malicious activity by matching file artifacts against the specific signature defined in the MSLRHv032aemadicius YARA rule. The SOC team should proactively hunt for this indicator within Azure Sentinel to uncover early-stage threats that may not yet trigger high-severity alerts, ensuring comprehensive coverage of low-fidelity but significant adversary behaviors.
rule MSLRHv032aemadicius
{
meta:
author="malware-lu"
strings:
$a0 = { E8 EB 0C 00 00 E8 F6 FF FF FF E8 F2 FF FF FF 83 C4 08 74 04 75 02 EB 02 EB 01 81 74 04 75 02 EB 02 EB 01 81 0F 31 50 0F 31 E8 0A 00 00 00 E8 EB 0C 00 00 E8 F6 FF FF FF E8 F2 FF FF FF 83 C4 08 2B 04 24 74 04 75 02 EB 02 EB 01 81 83 C4 04 E8 0A 00 00 00 E8 }
$a1 = { EB 05 E8 EB 04 40 00 EB FA E8 0A 00 00 00 E8 EB 0C 00 00 E8 F6 FF FF FF E8 F2 FF FF FF 83 C4 08 74 04 75 02 EB 02 EB 01 81 E8 0A 00 00 00 E8 EB 0C 00 00 E8 F6 FF FF FF E8 F2 FF FF FF 83 C4 08 74 04 75 02 EB 02 EB 01 81 50 E8 02 00 00 00 29 5A 58 6B C0 03 }
$a2 = { E8 EB 0C 00 00 E8 F6 FF FF FF E8 F2 FF FF FF 83 C4 08 74 04 75 02 EB 02 EB 01 81 74 04 75 02 EB 02 EB 01 81 0F 31 50 0F 31 E8 0A 00 00 00 E8 EB 0C 00 00 E8 F6 FF FF FF E8 F2 FF FF FF 83 C4 08 2B 04 24 74 04 75 02 EB 02 EB 01 81 83 C4 04 E8 0A 00 00 00 E8 EB 0C 00 00 E8 F6 FF FF FF E8 F2 FF FF FF 83 C4 08 3D FF FF FF 00 EB 01 68 EB 02 CD 20 EB 01 E8 76 1B EB 01 68 EB 02 CD 20 EB 01 E8 CC 66 B8 FE 00 74 04 75 02 EB 02 EB 01 81 66 E7 64 74 04 75 02 EB 02 EB 01 81 E8 0A 00 00 00 E8 EB 0C }
condition:
$a0 or $a1 or $a2 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 3 string patterns in its detection logic.
Here are 5 specific false positive scenarios for the MSLRHv032aemadicius detection rule, along with suggested filters and exclusions:
Scenario: Microsoft Defender Antivirus Scheduled Scans
MsMpEng.exe process when it performs a scheduled full scan or updates its virus definition database. During these operations, the engine loads various heuristic modules that match the “emadicius” pattern within temporary memory regions.--scheduled-scan and the parent process is MsMpEng.exe. Alternatively, create a rule exclusion for the file path C:\Program Files\Windows Defender\MsMpEng.exe during standard business hours (08:00–18:00).Scenario: SCCM/MECM Software Deployment Tasks
ccmsetup.exe and associated installation agents often spawn child processes that unpack compressed payloads. These temporary extraction activities can mimic the binary structure detected by the MSLRHv032aemadicius rule.ccmexec.exe or ccmsetup.exe. Add an exclusion for file paths under C:\Windows\CCM\ and C:\ProgramData\Microsoft\MSCCM\.Scenario: Active Directory Group Policy Updates
gpupdate.exe process interacts with the registry and file system to apply new policies. The rule may flag the policy engine’s interaction with specific XML configuration files as a potential anomaly matching