This rule identifies executable files that exhibit characteristics of the PseudoSigner01 tool, a utility often used by adversaries to create compact, unsigned PE files for stealthy payload delivery or initial access. Proactively hunting for these artifacts in Azure Sentinel allows the SOC to detect low-severity, potentially malicious binaries that may evade traditional signature-based detection, ensuring early visibility into suspicious code execution within the environment.
rule PseudoSigner01PECompact14Anorganix
{
meta:
author="malware-lu"
strings:
$a0 = { 90 90 90 90 68 [4] 67 64 FF 36 00 00 67 64 89 26 00 00 F1 90 90 90 90 EB 06 68 90 90 90 90 C3 9C 60 E8 02 90 90 90 33 C0 8B C4 83 C0 04 93 8B E3 8B 5B FC 81 }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Scenario: A developer or DevOps engineer uses Inno Setup or NSIS to package a custom internal tool or driver installer that includes a compressed PE section (often using LZMA or Deflate compression) to reduce file size. The “PseudoSigner” heuristic may flag the compressed header structure as anomalous if the digital signature is applied after compression or if the compression algorithm creates a specific byte pattern that mimics a known pseudo-signature.
C:\Builds\, D:\Artifacts\) or files with extensions like .exe created by known packaging tools (e.g., Inno Setup 6, NSIS). Consider whitelisting specific hash values of known internal installers.Scenario: An IT administrator deploys a legacy application update using Group Policy Preferences (GPP) or SCCM/MECM where the executable is stored in a compressed archive (e.g., .cab or .zip) and extracted to the client. The extraction process may leave a temporary file with a compressed PE structure that hasn’t been fully decompressed or re-signed, triggering the “Compact” and “Anorganix” (likely referring to a specific vendor or structural anomaly) heuristics.
%TEMP%, C:\Windows\Temp\, or C:\ProgramData\Microsoft\Windows\Group Policy\. Also, exclude files with paths containing SCCM, MECM, or GPP if the rule is not intended to catch malware hiding in these locations.Scenario: A security team runs a VirusTotal or ClamAV scan on a large corpus of internal binaries, or a CI/CD pipeline (e.g