This rule targets executable files exhibiting characteristics of the PseudoSigner tool, which adversaries use to apply fake digital signatures to malicious binaries to bypass trust-based security controls. Proactively hunting for these artifacts in Azure Sentinel allows the SOC to identify stealthy payloads that may have evaded initial detection by masquerading as trusted software, thereby reducing the risk of undetected lateral movement or persistence.
rule PseudoSigner01JDPack1xJDProtect09Anorganix
{
meta:
author="malware-lu"
strings:
$a0 = { 60 E8 22 00 00 00 5D 8B D5 81 ED 90 90 90 90 2B 95 90 90 90 90 81 EA 06 90 90 90 89 95 90 90 90 90 83 BD 45 00 01 00 01 E9 }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
app_logs_20231027.zip) on a build server. The YARA rule’s generic byte patterns for “packers” or “signers” may match the internal structure of the ZIP container or the specific compression algorithm headers, triggering a false positive on a standard file transfer.
.zip, .rar, .7z, or .tar.gz from this rule, or add a condition to ignore files larger than 50MB, as large archives are common in CI/CD pipelines.C:\Sysinternals\ directory or known administrative tool paths (e.g., C:\Tools\, C:\Admin\), and whitelist specific executable names like procexp.exe or procmon.exe.