This detection identifies potential open-source code crypter activity that may indicate an adversary attempting to obfuscate malicious scripts within legitimate development environments. A proactive hunt is essential in Azure Sentinel to uncover early-stage supply chain compromises where attackers leverage trusted open-source tools to bypass traditional signature-based defenses.
rule OpenSourceCodeCrypterp0ke
{
meta:
author="malware-lu"
strings:
$a0 = { 55 8B EC B9 09 00 00 00 6A 00 6A 00 49 75 F9 53 56 57 B8 34 44 40 00 E8 28 F8 FF FF 33 C0 55 68 9F 47 40 00 64 FF 30 64 89 20 BA B0 47 40 00 B8 1C 67 40 00 E8 07 FD FF FF 8B D8 85 DB 75 07 6A 00 E8 C2 F8 FF FF BA 28 67 40 00 8B C3 8B 0D 1C 67 40 00 E8 F0 E0 FF FF BE 01 00 00 00 B8 2C 68 40 00 E8 E1 F0 FF FF BF 0A 00 00 00 8D 55 EC 8B C6 E8 92 FC FF FF 8B 4D EC B8 2C 68 40 00 BA BC 47 40 00 E8 54 F2 FF FF A1 2C 68 40 00 E8 52 F3 FF FF 8B D0 B8 20 67 40 00 E8 A2 FC FF FF 8B D8 85 DB 0F 84 52 02 00 00 B8 24 67 40 00 8B 15 20 67 40 00 E8 78 F4 FF FF B8 24 67 40 00 E8 7A F3 FF FF 8B D0 8B C3 8B 0D 20 67 40 00 E8 77 E0 FF FF 8D 55 E8 A1 24 67 40 00 E8 42 FD FF FF 8B 55 E8 B8 24 67 40 00 }
condition:
$a0
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 5 specific false positive scenarios for the OpenSourceCodeCrypterp0ke detection rule, including suggested filters and exclusions:
Scenario: Automated Dependency Scanning in CI/CD Pipelines
npm, pip, or maven) and compile them within ephemeral containers. The YARA rule may trigger when these build agents unpack archives containing legitimate open-source code that matches the crypter signature.GITHUB_ACTIONS, JENKINS_BUILD_USER) or restrict detection to exclude file paths within known CI workspace directories (e.g., C:\hostedtoolcache\windows\ or /var/lib/jenkins/workspace/*).Scenario: Developer Local Build and Compilation Tasks
devenv.exe, java.exe, msbuild.exe) when operating within standard project directories (e.g., C:\DevProjects\* or /home/dev/*). Additionally, filter out events where the parent process is a known IDE.Scenario: Scheduled Antivirus and EDR Scanning Jobs