This rule detects the presence of the PELOCKnt204 YARA signature, which identifies specific executable files that may be associated with low-severity malware or obfuscated payloads. Proactively hunting for this indicator in Azure Sentinel allows the SOC team to identify potentially compromised hosts or dormant threats before they escalate, ensuring early containment within the environment.
rule PELOCKnt204
{
meta:
author="malware-lu"
strings:
$a0 = { EB 03 CD 20 C7 1E EB 03 CD 20 EA 9C EB 02 EB 01 EB 01 EB 60 }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are specific false positive scenarios for the YARA rule PELOCKnt204 (typically associated with detecting specific PE file characteristics, often related to packing, specific compiler artifacts, or known benign software signatures that mimic malicious patterns) and suggested exclusions:
Microsoft Visual Studio Build Tools & C++ Compiler Artifacts
cl.exe (Microsoft C++ compiler) or link.exe to build native applications. The resulting PE binaries may contain specific section headers, import tables, or debug information that matches the heuristic patterns in PELOCKnt204. This is common in CI/CD pipelines where build agents compile code on Windows servers.C:\Program Files (x86)\Microsoft Visual Studio\, C:\BuildAgent\) or files with extensions .obj, .lib, and .pdb that are part of the build output. Alternatively, exclude processes named cl.exe, link.exe, or msbuild.exe that are writing these files.Adobe Creative Suite & Font Embedding
C:\Program Files\Adobe\ or C:\Program Files (x86)\Adobe\. Specifically, allow executables and DLLs from known Adobe components such as Photoshop.exe, Illustrator.exe, or AcroRd32.exe.NVIDIA Graphics Driver Updates & Shader Compilation