This detection identifies active Perl application states that may indicate adversary use of scripting for post-exploitation tasks or lateral movement within the environment. Proactively hunting for these signals in Azure Sentinel allows the SOC team to distinguish legitimate administrative activity from potential low-and-slow threats leveraging Perl scripts to evade standard signature-based defenses.
rule PerlApp602ActiveState
{
meta:
author="malware-lu"
strings:
$a0 = { 68 2C EA 40 00 FF D3 83 C4 0C 85 C0 0F 85 CD 00 00 00 6A 09 57 68 20 EA 40 00 FF D3 83 C4 0C 85 C0 75 12 8D 47 09 50 FF 15 1C D1 40 00 59 A3 B8 07 41 00 EB 55 6A 08 57 68 14 EA 40 00 FF D3 83 C4 0C 85 C0 75 11 8D 47 08 50 FF 15 1C D1 40 00 59 89 44 24 10 EB 33 6A 09 57 68 08 EA 40 00 FF D3 83 C4 0C 85 C0 74 22 6A 08 57 68 FC E9 40 00 FF D3 83 C4 0C 85 C0 74 11 6A 0B 57 68 F0 E9 40 00 FF D3 83 C4 0C 85 C0 75 55 }
$a1 = { 68 9C E1 40 00 FF 15 A4 D0 40 00 85 C0 59 74 0F 50 FF 15 1C D1 40 00 85 C0 59 89 45 FC 75 62 6A 00 8D 45 F8 FF 75 0C F6 45 14 01 50 8D 45 14 50 E8 9B 01 00 00 83 C4 10 85 C0 0F 84 E9 00 00 00 8B 45 F8 83 C0 14 50 FF D6 85 C0 59 89 45 FC 75 0E FF 75 14 FF 15 78 D0 40 00 E9 C9 00 00 00 68 8C E1 40 00 FF 75 14 50 }
condition:
$a0 or $a1
}
This YARA rule can be deployed in the following contexts:
This rule contains 2 string patterns in its detection logic.
Here are 4 specific false positive scenarios for the PerlApp602ActiveState detection rule, including suggested filters and exclusions:
Scenario: ActiveState Package Manager Scheduled Updates
astate-update.exe or perlapp-updater) on a scheduled basis to check for new Perl package versions. This process executes the YARA rule’s signature while scanning local repositories, triggering an alert despite being a known administrative task.Process.Path contains "C:\Program Files\ActiveState\bin\" AND Process.Name in ["astate-update.exe", "perlapp-updater.exe"].Scenario: CI/CD Pipeline Artifact Deployment (Jenkins/GitLab)
Process.Parent.Name in ["java.exe", "node.exe"] AND User.AccountName contains "jenkins" OR "gitlab-runner" AND Process.Path starts with "C:\ProgramData\Jenkins\".Scenario: Automated Compliance Scanning by Qualys or Tenable