This detection identifies adversaries attempting to evade timeline-based analysis by generating files with randomized timestamps that disrupt standard forensic chronology. Proactive hunting for this behavior in Azure Sentinel is essential to uncover stealthy post-compromise activities where attackers manipulate metadata to obscure their initial access and lateral movement patterns.
rule RandomTimestampGenerator: sharedcode
{
meta:
copyright = "2015 Novetta Solutions"
author = "Novetta Threat Research & Interdiction Group - trig@novetta.com"
Source = "RT_RCDATA_101.bin.bin joanap baseline sample"
strings:
/*
66 81 44 24 0C FE FF add [esp+1Ch+SystemTime.wYear], 0FFFEh
FF D6 call esi ; rand
99 cdq
B9 0C 00 00 00 mov ecx, 0Ch
F7 F9 idiv ecx
42 inc edx
66 89 54 24 0E mov [esp+1Ch+SystemTime.wMonth], dx
FF D6 call esi ; rand
99 cdq
B9 1C 00 00 00 mov ecx, 1Ch
F7 F9 idiv ecx
42 inc edx
66 89 54 24 12 mov [esp+1Ch+SystemTime.wDay], dx
FF D6 call esi ; rand
99 cdq
B9 17 00 00 00 mov ecx, 17h
F7 F9 idiv ecx
42 inc edx
66 89 54 24 14 mov [esp+1Ch+SystemTime.wHour], dx
FF D6 call esi ; rand
99 cdq
B9 3B 00 00 00 mov ecx, 3Bh
F7 F9 idiv ecx
42 inc edx
66 89 54 24 16 mov [esp+1Ch+SystemTime.wMinute], dx
FF D6 call esi ; rand
99 cdq
B9 3B 00 00 00 mov ecx, 3Bh
F7 F9 idiv ecx
*/
$a = { 66 81 [3] FE FF FF [1-4] 99 B9 0C 00 00 00 F7 [1-4] 42 66 89 [3] FF D6 99 B9 1C 00 00 00 F7 [1-4] 42 66 89 [3] FF D6 99 B9 17 00 00 00 F7 [1-4] 42 66 89 [3] FF D6 99 B9 3B 00 00 00 F7 [1-4] 42 66 89 [3] FF D6 99 B9 3B 00 00 00 F7 }
condition:
$a in ((pe.sections[pe.section_index(".text")].raw_data_offset)..(pe.sections[pe.section_index(".text")].raw_data_offset + pe.sections[pe.section_index(".text")].raw_data_size))
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 5 specific false positive scenarios for the RandomTimestampGenerator detection rule in an enterprise environment, along with suggested filters or exclusions:
Scenario: Automated Backup and Snapshot Creation
VeeamSvc, CommServeAgent) and restrict the rule to only trigger on file extensions not typically used for backups (excluding .vbk, .bmr, .azbackup).Scenario: Log Aggregation and Rotation Agents
syslog or IIS logs), these agents may create compressed archives (.gz, .zip) where the archive timestamp is randomized to prevent collision with existing files during concurrent rotation cycles on multi-core servers.\Program Files\SplunkUniversalForwarder\bin\splunk-forwarder.exe, \opt\datadog-agent) and exclude file operations targeting standard log directories (e.g., C:\Windows\System32\winevt\Logs or /var/log).Scenario: Software Deployment and Patch Management