This detection identifies the presence of Obsidium software components within the environment by matching file signatures against a specific YARA rule to establish a baseline for legitimate application behavior. Proactively hunting for this signature in Azure Sentinel allows the SOC team to verify authorized installations and quickly distinguish genuine Obsidium processes from potential masquerading threats or unauthorized software deployments.
rule Obsidium1322ObsidiumSoftware
{
meta:
author="malware-lu"
strings:
$a0 = { EB 04 [4] E8 2A 00 00 00 EB 03 [3] EB 04 [4] 8B 54 24 0C EB 02 [2] 83 82 B8 00 00 00 26 EB 04 [4] 33 C0 EB 02 [2] C3 EB 01 ?? EB 03 [3] 64 67 FF 36 00 00 EB 02 [2] 64 67 89 26 00 00 EB 02 [2] EB 01 ?? 50 EB 04 [4] 33 C0 EB 04 [4] 8B 00 EB 02 [2] C3 EB 03 [3] E9 FA 00 00 00 EB 04 [4] E8 D5 FF FF FF EB 02 [2] EB 04 [4] 58 EB 01 ?? EB 01 ?? 64 67 8F 06 00 00 EB 01 ?? 83 C4 04 EB 04 }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 4 specific false positive scenarios for the Obsidium1322ObsidiumSoftware detection rule, along with targeted filters and exclusions:
Scenario: Scheduled Endpoint Protection Updates
obsidium-updater.exe service spawns child processes to download patches and modify registry keys related to policy enforcement, which mimics the behavioral signature of a new software installation or configuration change detected by the YARA rule.C:\Program Files\Obsidium\Agent\obsidium-updater.exe and its associated scheduled task name \Microsoft\Windows\TaskScheduler\ObsidiumDailyUpdate. Alternatively, filter out events where the parent process is svchost.exe with the service name ObsidiumUpdateService during the 01:30–02:30 AM window.Scenario: Group Policy Object (GPO) Deployment
User context is SYSTEM and the Source Computer belongs to the IT-Admins Organizational Unit. Additionally, filter out alerts generated when the process command line contains the flag /gpo-refresh or originates from the parent process gpupdate.exe.