This rule detects the presence of SDProtector, a commercial software protection tool frequently leveraged by threat actors to obfuscate malicious payloads and hinder static analysis. Proactively hunting for this indicator in Azure Sentinel allows the SOC team to identify potentially compromised endpoints or staging environments where adversaries are using commercial packers to mask their intent before execution.
rule SDProtectorBasicProEdition112RandyLi
{
meta:
author="malware-lu"
strings:
$a0 = { 55 8B EC 6A FF 68 1D 32 13 05 68 88 88 88 08 64 A1 00 00 00 00 50 64 89 25 00 00 00 00 58 64 A3 00 00 00 00 58 58 58 58 8B E8 E8 3B 00 00 00 E8 01 00 00 00 FF 58 05 53 00 00 00 51 8B 4C 24 10 89 81 B8 00 00 00 B8 55 01 00 00 89 41 20 33 C0 89 41 04 89 41 08 89 41 0C 89 41 10 59 C3 C3 C3 C3 C3 C3 C3 C3 C3 C3 C3 C3 C3 33 C0 64 FF 30 64 89 20 9C 80 4C 24 01 01 9D 90 90 C3 C3 C3 C3 C3 C3 C3 C3 C3 C3 C3 C3 64 8F 00 58 74 07 75 05 19 32 67 E8 E8 74 27 75 25 EB 00 EB FC 68 39 44 CD 00 59 9C 50 74 0F 75 0D E8 59 C2 04 00 55 8B EC E9 FA FF FF 0E E8 EF FF FF FF 56 57 53 78 03 79 01 E8 68 A2 AF 47 01 59 E8 01 00 00 00 FF 58 05 7B 03 00 00 03 C8 74 C4 75 C2 E8 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 E2 }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Scenario: A developer or IT administrator manually compiles a small utility or internal tool using the SDProtector Basic/Pro Edition (v112) to obfuscate the binary before deploying it to a test environment or staging server.
C:\Users\*\\Projects\\build\\, C:\Temp\\builds\\) or exclude files with specific extensions (.exe, .dll) if the parent process is a known compiler or build tool (e.g., msbuild.exe, dotnet.exe, csc.exe).Scenario: A legacy application installer or a specific vendor’s software package includes a component protected by SDProtector v112. When the installer runs, the protected binary is extracted to a temporary directory and executed, triggering the YARA rule.
C:\Windows\Temp\\, C:\Users\*\\AppData\\Local\\Temp\\) if the parent process is a known installer (e.g., msiexec.exe, setup.exe, install.exe) or if the file path contains vendor-specific identifiers (e.g., \\VendorName\\, \\Installer\\).Scenario: A scheduled maintenance job or a custom script uses SDProtector to protect a small helper script or executable that runs periodically to perform log rotation, data cleanup, or health checks.
svchost.exe with taskschd.dll loaded, or TaskScheduler.exe) or if the file name matches known maintenance patterns (e.g., cleanup.exe, logrotate.exe, healthcheck.exe) and resides in