This detection identifies potential software supply chain compromises or unauthorized application deployments by flagging files matching the specific Obsidium Software YARA signature within the Azure Sentinel environment. Proactively hunting for this indicator allows the SOC team to validate legitimate business applications against known benign patterns and rapidly isolate any anomalous instances that could signal early-stage lateral movement or malicious code injection.
rule Obsidium133720070623ObsidiumSoftware
{
meta:
author="malware-lu"
strings:
$a0 = { EB 02 [2] E8 27 00 00 00 EB 03 [3] EB 01 ?? 8B 54 24 0C EB 03 [3] 83 82 B8 00 00 00 23 EB 03 [3] 33 C0 EB 02 [2] C3 EB 01 ?? EB 03 [3] 64 67 FF 36 00 00 EB 04 [4] 64 67 89 26 00 00 EB 01 ?? EB 01 ?? 50 EB 02 [2] 33 C0 EB 01 ?? 8B 00 EB 04 [4] C3 EB 02 [2] E9 FA 00 00 00 EB 04 [4] E8 D5 FF FF FF EB 01 ?? EB 01 ?? 58 EB 04 [4] EB 01 ?? 64 67 8F 06 00 00 EB 02 [2] 83 C4 04 EB 01 ?? E8 F7 26 00 00 }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 4 specific false positive scenarios for the Obsidium133720070623ObsidiumSoftware detection rule, including suggested filters and exclusions:
Scenario: Automated Backup Execution by Veeam Backup & Replication
svc_veeam) executes the ObsidiumSoftware agent binary on the file server to ensure backup integrity before archiving. This triggers the rule because the agent performs a signature scan that matches the YARA pattern during high-I/O periods.Process Parent Name is Veeam.Backup.Service.exe AND User Account contains svc_veeam.Scenario: Scheduled Patch Deployment via Microsoft Endpoint Configuration Manager (SCCM)
ObsidiumSetup.exe) which runs with elevated privileges on all domain-joined workstations, triggering the detection logic as it writes registry keys and updates binaries.02:00 and 04:00 (local server time) on weekdays where the Process Command Line contains keywords like /install, /update, or SCCM.Scenario: Endpoint Protection Scanning by CrowdStrike Falcon
FalconService) scans the specific executable path associated with Obsidium, it generates a file hash that coincidentally