This YARA rule targets the execution of the MSLRHv32aemadicius binary, a known malware component often used for initial access or lateral movement within Windows environments. Proactively hunting for this signature in Azure Sentinel allows the SOC team to identify compromised endpoints early, preventing potential privilege escalation or data exfiltration before the adversary establishes a persistent foothold.
rule MSLRHv32aemadicius
{
meta:
author="malware-lu"
strings:
$a0 = { EB 05 E8 EB 04 40 00 EB FA E8 0A 00 00 00 E8 EB 0C 00 00 E8 F6 FF FF FF E8 F2 FF FF FF 83 C4 08 74 04 75 02 EB 02 EB 01 81 E8 0A 00 00 00 E8 EB 0C 00 00 E8 F6 FF FF FF E8 F2 FF FF FF 83 C4 08 74 04 75 02 EB 02 EB 01 81 50 E8 02 00 00 00 29 5A 58 6B C0 03 E8 02 00 00 00 29 5A 83 C4 04 58 74 04 75 02 EB 02 EB 01 81 0F 31 50 0F 31 E8 0A 00 00 00 E8 EB 0C 00 00 E8 F6 FF FF FF E8 F2 FF FF FF 83 C4 08 2B 04 24 74 04 75 02 EB 02 EB 01 81 83 C4 04 E8 0A 00 00 00 E8 EB 0C 00 00 E8 F6 FF FF FF E8 F2 FF FF FF 83 C4 08 3D FF 0F 00 00 EB 01 68 EB 02 CD 20 EB 01 E8 76 1B EB 01 68 EB 02 CD 20 EB 01 E8 CC 66 B8 FE 00 74 04 75 02 EB 02 EB 01 81 66 E7 64 E8 0A 00 00 00 E8 EB 0C 00 00 E8 F6 FF FF FF E8 F2 FF FF FF 83 C4 08 74 04 75 02 EB 02 EB 01 81 0F 31 50 0F 31 }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
msiexec.exe process to install or update components, the YARA rule may flag the installer executable or the temporary files created during the GPO push.
C:\Windows\Installer\ or C:\Program Files (x86)\ where the parent process is gpupdate.exe or svchost.exe (specifically the gpupdate service host).msiexec.exe to repair or update 32-bit Microsoft Office components (e.g., Office15 or Office16 32-bit installations) on workstations. The YARA rule might trigger on the specific version string or resource section of the 32-bit MSI package.
/i (install) or /f (repair) flags and the target path includes Microsoft Office or Office15/Office16, specifically when the process bitness is 32-bit (x86).msiexec.exe to apply patches. These installers may match the YARA signature if they share common resource structures or version strings with the targeted malware family.