This detection identifies the execution of a specific software component associated with BoB Bob Soft, which may indicate legitimate application activity or an adversary leveraging known plugins to establish persistence within the environment. A SOC team should proactively hunt for this behavior in Azure Sentinel to validate whether these plugin executions align with expected business processes or represent a potential foothold for lateral movement and data exfiltration by threat actors.
rule PluginToExev101BoBBobSoft
{
meta:
author="malware-lu"
strings:
$a0 = { E8 00 00 00 00 29 C0 5D 81 ED C6 41 40 00 50 8F 85 71 40 40 00 50 FF 95 A5 41 40 00 89 85 6D 40 40 00 FF 95 A1 41 40 00 50 FF 95 B5 41 40 00 80 38 00 74 16 8A 08 80 F9 22 75 07 50 FF 95 B9 41 40 00 89 85 75 40 40 00 EB 6C 6A 01 8F 85 71 40 40 00 6A 58 6A 40 FF 95 A9 41 40 00 89 85 69 40 40 00 89 C7 68 00 08 00 00 6A 40 FF 95 A9 41 40 00 89 47 1C C7 07 58 00 00 00 C7 47 20 00 08 00 00 C7 47 18 01 00 00 00 C7 47 34 04 10 88 00 8D 8D B9 40 40 00 89 4F 0C 8D 8D DB 40 40 00 89 4F 30 FF B5 69 40 40 00 FF 95 95 41 40 00 FF 77 1C 8F 85 75 40 40 00 8B 9D 6D 40 40 00 60 6A 00 6A 01 53 81 C3 [3] 00 FF D3 61 6A 00 68 44 69 45 50 FF B5 75 40 40 00 6A 00 81 C3 [2] 00 00 FF D3 83 C4 10 83 BD 71 40 40 00 00 74 10 FF 77 1C FF 95 AD 41 40 00 57 FF 95 AD 41 40 00 6A 00 FF 95 9D 41 40 00 }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 4 specific false positive scenarios for the PluginToExev101BoBBobSoft detection rule, including suggested filters and exclusions:
Scenario: Scheduled Backup Agent Execution
BobSoft plugin to archive event logs from the Exchange server (Exev101) before compression. This process triggers the YARA rule due to the specific file signature of the BobSoft plugin during high-volume I/O operations.DOMAIN\svc_backup_agent) and restrict the detection scope to exclude processes running under the parent process VeeamBackupService.exe or commvault.cmd.Scenario: Admin-Initiated Plugin Update via PowerShell
Update-BobSoftPlugin.ps1) which loads the plugin DLL into memory, causing the YARA rule to fire as it scans the newly loaded binary structure.powershell.exe and the command line contains specific keywords like -Update, -Install, or references to the BobSoft package path (e.g., C:\Program Files\BobSoft\Updater).Scenario: Third-Party Compliance Scanner Activity
Exev101, mimicking the behavior of a malicious plugin injection detected by the rule