This detection identifies adversaries leveraging registry modifications to trigger executable processes, a technique often used by attackers to establish persistence or execute payloads while evading standard process creation monitoring. Proactively hunting for this behavior in Azure Sentinel is essential because low-severity signals like this frequently represent early-stage lateral movement or fileless attacks that may escalate into critical incidents if not correlated with broader telemetry.
rule Reg2Exe220221byJanVorel
{
meta:
author="malware-lu"
strings:
$a0 = { 6A 00 E8 7D 12 00 00 A3 A0 44 40 00 E8 79 12 00 00 6A 0A 50 6A 00 FF 35 A0 44 40 00 E8 0F 00 00 00 50 E8 69 12 00 00 CC CC CC CC CC CC CC CC CC 68 2C 02 00 00 68 00 00 00 00 68 B0 44 40 00 E8 3A 12 00 00 83 C4 0C 8B 44 24 04 A3 B8 44 40 00 68 00 00 00 00 68 A0 0F 00 00 68 00 00 00 00 E8 32 12 00 00 A3 B0 44 40 00 68 F4 01 00 00 68 BC 44 40 00 FF 35 B8 44 40 00 E8 1E 12 00 00 B8 BC 44 40 00 89 C1 8A 30 40 80 FE 5C 75 02 89 C1 80 FE 00 75 F1 C6 01 00 E8 EC 18 00 00 E8 28 16 00 00 E8 4A 12 00 00 68 00 FA 00 00 68 08 00 00 00 FF 35 B0 44 40 00 E8 E7 11 00 00 A3 B4 44 40 00 8B 15 D4 46 40 00 E8 65 0A 00 00 BB 00 00 10 00 B8 01 00 00 00 E8 72 0A 00 00 74 09 C7 00 01 00 00 00 83 C0 04 A3 D4 46 40 00 FF 35 B4 44 40 00 E8 26 05 00 00 8D 0D B8 46 40 00 5A E8 CF 0F 00 00 FF 35 B4 44 40 00 FF 35 B8 46 40 00 E8 EE 06 00 00 8D 0D B4 46 40 00 5A E8 }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 3-5 specific false positive scenarios for the Reg2Exe220221byJanVorel detection rule, which typically targets suspicious registry-to-executable interactions often associated with fileless attacks or living-off-the-land techniques:
Scenario: Windows Update Agent Execution via Registry Trigger
WindowsUpdate.exe process frequently modifies the registry to check for updates and subsequently launches background workers (e.g., UsoSvc) based on specific registry keys under HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate. This legitimate behavior can mimic a malicious “Registry-to-Executable” chain.C:\Windows\System32\svchost.exe (specifically the Wuauserv service) and the child process name is UsoSvc.exe or Microsoft.Update.Client.Scenario: Antivirus Real-Time Scanning Engine Initialization
HKLM\SOFTWARE\<Vendor>\Settings) before spawning a dedicated scanning executable (e.g., falcon.sys helper or mfevcs.exe).C:\Program Files\CrowdStrike\Falcon\CSFalconService.exe or C:\Program Files\McAfee\Agent\x86\mfevcs.exe.Scenario: Scheduled Task Execution via Registry Configuration