This detection identifies potential code signing anomalies where executables exhibit characteristics of pseudo-signers or unorganized digital signatures, which may indicate an adversary attempting to bypass trust mechanisms by masquerading as legitimate software. A proactive hunt is essential in Azure Sentinel to uncover these subtle indicators that often evade standard signature-based defenses, allowing the SOC team to validate the authenticity of signed binaries before they execute within the environment.
rule PseudoSigner01ASProtectAnorganix
{
meta:
author="malware-lu"
strings:
$a0 = { 60 90 90 90 90 90 90 5D 90 90 90 90 90 90 90 90 90 90 90 03 DD E9 }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 4 specific false positive scenarios for the PseudoSigner01ASProtectAnorganix detection rule, including suggested filters and exclusions:
Scenario: Scheduled Antivirus Engine Updates by AS Protect
asprotect.exe process often spawns child processes that generate pseudo-signatures matching the Anorganix pattern due to shared cryptographic libraries or embedded certificate chains.C:\Program Files\ASProtect\Updater\asprotect_updater.exe) and exclude any process tree where the parent is this updater service from triggering the rule during the defined maintenance window (e.g., 02:00–04:00 UTC).Scenario: Microsoft Office Add-in Installation via Group Policy
msiexec.exe or setup.exe processes install the add-in on user machines during logon.msiexec.exe and the command line contains the specific Product ID (GUID) of the Anorganix Office Add-in, or exclude the installation directory path C:\Program Files\Anorganix\OfficeAddin\ entirely.Scenario: CI/CD Pipeline Artifact Signing in Dev Environments