This detection identifies potentially malicious Win32 executables that exhibit suspicious code signing characteristics associated with the Anorganix pseudo-signing pattern, which often indicates an adversary attempting to bypass trust mechanisms through forged or reused certificates. A proactive hunt is essential in Azure Sentinel to uncover stealthy initial access attempts where attackers leverage these specific signature anomalies to establish persistence while evading standard signature-based defenses.
rule PseudoSigner02LCCWin321xAnorganix
{
meta:
author="malware-lu"
strings:
$a0 = { 64 A1 01 00 00 00 55 89 E5 6A FF 68 [4] 68 9A 10 40 90 50 }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 5 specific false positive scenarios for the PseudoSigner02LCCWin321xAnorganix detection rule, including suggested filters and exclusions:
Scenario: Legitimate execution of Microsoft Office Click-to-Run updates during business hours.
OfficeClickToRun.exe) often launches temporary processes with pseudo-signed certificates that match the “Anorganix” signature pattern while downloading or installing patches.C:\Program Files\Microsoft Office\root\Office16 and specifically filter for parent process names ClickToRun.exe or OfficeBackgroundTaskHandler.exe.Scenario: Scheduled task execution of Sysinternals Process Explorer or Process Monitor by security analysts.
ProcExp.exe, ProcMon.exe, and Pstools.exe located within the standard administrative tool directory (e.g., C:\Tools\Sysinternals\).Scenario: Automated deployment of VMware Horizon or Citrix Workspace client updates.
HvAgent.exe (VMware) or wfcrun.exe (Citrix) and the file path resides under C:\Program Files\VMware or `C:\Program Files\C