This hypothesis targets the presence of the SDProtector Pro Edition 1.16.16 malware variant, a known commercial packer often abused by threat actors to obfuscate malicious payloads and evade static analysis. Proactively hunting for this specific signature in Azure Sentinel allows the SOC team to identify compromised endpoints or suspicious processes that may be leveraging this packer to hide their activity before they establish persistence or execute further post-exploitation actions.
rule SDProtectorProEdition116RandyLi
{
meta:
author="malware-lu"
strings:
$a0 = { 55 8B EC 6A FF 68 1D 32 13 05 68 88 88 88 08 64 A1 00 00 00 00 50 64 89 25 00 00 00 00 58 64 A3 00 00 00 00 58 58 58 58 8B E8 E8 3B 00 00 00 E8 01 00 00 00 FF 58 05 53 00 00 00 51 8B 4C 24 10 89 81 B8 00 00 00 B8 55 01 00 00 89 41 18 33 C0 89 41 04 89 41 }
$a1 = { 55 8B EC 6A FF 68 1D 32 13 05 68 88 88 88 08 64 A1 00 00 00 00 50 64 89 25 00 00 00 00 58 64 A3 00 00 00 00 58 58 58 58 8B E8 E8 3B 00 00 00 E8 01 00 00 00 FF 58 05 53 00 00 00 51 8B 4C 24 10 89 81 B8 00 00 00 B8 55 01 00 00 89 41 18 33 C0 89 41 04 89 41 08 89 41 0C 89 41 10 59 C3 C3 C3 C3 C3 C3 C3 C3 C3 C3 C3 C3 C3 33 C0 64 FF 30 64 89 20 9C 80 4C 24 01 01 9D 90 90 C3 C3 C3 C3 C3 C3 C3 C3 C3 C3 C3 C3 64 8F 00 58 74 07 75 05 19 32 67 E8 E8 74 27 75 25 EB 00 EB FC 68 39 44 CD 00 59 9C 50 74 0F 75 0D E8 59 C2 04 00 55 8B EC E9 FA FF FF 0E E8 EF FF FF FF 56 57 53 78 03 79 01 E8 68 A2 AF 47 01 59 E8 01 00 00 00 FF 58 05 93 03 00 00 03 C8 74 C4 75 C2 E8 }
condition:
$a0 at pe.entry_point or $a1 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 2 string patterns in its detection logic.
Scenario: A developer or DevOps engineer runs the SDProtectorPro executable locally to test application obfuscation or protection features before deployment.
C:\Users\<User>\Projects\, C:\temp\, or specific CI/CD agent workspaces) and exclude processes spawned by known IDEs (e.g., devenv.exe, code.exe) or build tools (e.g., msbuild.exe, dotnet.exe).Scenario: An automated scheduled task or CI/CD pipeline job executes SDProtectorPro as part of a post-build step to apply code signing or protection to release artifacts.
agent.exe for Azure DevOps, jenkins.exe, or github-runner.exe) or where the command line arguments contain specific build-related flags (e.g., /build, /sign, or output path arguments pointing to \\builds\ or \\artifacts\).Scenario: A security team or QA engineer performs a manual test of the protection tool in an isolated lab environment or on a non-production test server.
Lab-Hosts, QA-Test-Bench) or exclude file paths containing keywords like lab, test, qa, or sandbox in the directory structure.Scenario: A third-party application installer or updater bundles SDProtectorPro as a dependency or uses it internally to protect its own components during installation.
msiexec.exe,