This rule targets a specific YARA signature that likely identifies a known malware family or suspicious code pattern, potentially indicating the presence of a low-severity threat such as a web shell, script-based payload, or minor variant of a common malware strain. Proactively hunting for this signature in Azure Sentinel allows the SOC team to detect early-stage infections or dormant threats that may not yet trigger higher-severity alerts, enabling faster containment and reducing the risk of lateral movement or data exfiltration.
rule MSLRHv032afakeBJFNT13emadicius
{
meta:
author="malware-lu"
strings:
$a0 = { EB 03 3A 4D 3A 1E EB 02 CD 20 9C EB 02 CD 20 EB 02 CD 20 60 EB 02 C7 05 EB 02 CD 20 E8 03 00 00 00 E9 EB 04 58 40 50 C3 61 9D 1F EB 05 E8 EB 04 40 00 EB FA E8 0A 00 00 00 E8 EB 0C 00 00 E8 F6 FF FF FF E8 F2 FF FF FF 83 C4 08 74 04 75 02 EB 02 EB 01 81 50 E8 02 00 00 00 29 5A 58 6B C0 03 E8 02 00 00 00 29 5A 83 C4 04 58 74 04 75 02 EB 02 EB 01 81 0F 31 50 0F 31 E8 0A 00 00 00 E8 EB 0C 00 00 E8 F6 FF FF FF E8 F2 FF FF FF 83 C4 08 2B 04 24 74 04 75 02 EB 02 EB 01 }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
C:\Builds\, C:\Jenkins\workspace\) or exclude processes where the parent process is cmake.exe, ninja.exe, or msbuild.exe..tmp files created during the transfer or execution of these scripts, especially if they are signed by a generic CA or lack a specific enterprise signature.
.tmp, .ps1, or .bat that are located in C:\Windows\Temp\ or C:\Users\<User>\AppData\Local\Temp\ and were created within the last 15 minutes.setup.exe for a new application like Zoom or Slack). The YARA rule may match the specific version string or resource section of the installer, which coincidentally overlaps with the malware’s fingerprint.
C:\Program Files\Zoom\, `C:\Program Files\