This YARA rule targets the Obsidium1339ObsidiumSoftware signature, which likely identifies a specific low-severity software artifact or benign tool that may be leveraged by adversaries for initial access or persistence. Proactively hunting for this indicator in Azure Sentinel allows the SOC team to distinguish between expected third-party components and potential stealthy implantations before they escalate in severity or impact.
rule Obsidium1339ObsidiumSoftware
{
meta:
author="malware-lu"
strings:
$a0 = { EB 02 [2] E8 29 00 00 00 EB 03 [3] EB 01 ?? 8B 54 24 0C EB 04 [4] 83 82 B8 00 00 00 28 EB 02 [2] 33 C0 EB 02 [2] C3 EB 03 [3] EB 04 [4] 64 67 FF 36 00 00 EB 03 [3] 64 67 89 26 00 00 EB 01 ?? EB 01 ?? 50 EB 03 [3] 33 C0 EB 03 [3] 8B 00 EB 04 [4] C3 EB 04 [4] E9 FA 00 00 00 EB 03 [3] E8 D5 FF FF FF EB 02 [2] EB 04 [4] 58 EB 03 [3] EB 04 [4] 64 67 8F 06 00 00 EB 03 [3] 83 C4 04 EB 04 [4] E8 CF 27 00 00 }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
msiexec.exe or setup.exe and the file path contains \Obsidian\ or \Obsidian Installer\. Additionally, exclude if the binary name is Obsidian.exe and the version string matches the expected release version.Obsidian.exe and the command line contains arguments like --sync, --index, or --background. Also, exclude if the parent process is explorer.exe or winlogon.exe and the working directory is within the user’s %APPDATA%\obsidian\ or %LOCALAPPDATA%\obsidian\ directory.MsMpEng.exe (Microsoft Defender), CrowdStrike Falcon, or CarbonBlack. Also, exclude if the file path is located in a temporary directory like %TEMP% or if the process is running from a read-only mount or shadow copy.