This detection identifies potential adversary activity involving the execution of pseudo-signed binaries or specific package structures that may indicate early-stage reconnaissance or supply chain compromise. A proactive hunt is essential to validate these low-severity signals and uncover hidden threats that might evade standard signature-based defenses within the Azure Sentinel environment.
rule PseudoSigner02DxPack10Anorganix
{
meta:
author="malware-lu"
strings:
$a0 = { 60 E8 00 00 00 00 5D 8B FD 81 ED 90 90 90 90 2B B9 00 00 00 00 81 EF 90 90 90 90 83 BD 90 90 90 90 90 0F 84 00 00 00 00 }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 5 specific false positive scenarios for the PseudoSigner02DxPack10Anorganix detection rule, including context and suggested filters:
Antivirus Engine Signature Updates
PseudoSigner signature pattern due to shared code libraries in the update payload.MsMpEng.exe, Csfalcon.exe, or CrowdStrikeService.exe when they are executing from the standard installation directory (e.g., C:\Program Files\Microsoft Defender\).Patch Management Deployment Agents
C:\Windows\CCM\Cache or C:\ProgramData\Ivanti, specifically targeting files with extensions .msi, .cab, and .log generated during the “Software Update Service” run time.Enterprise Backup Verification Jobs
DxPack10.