This detection identifies potentially stealthy malware or suspicious scripts that utilize specific R3 architecture characteristics while lacking standard FSG2 method signatures, suggesting an attempt to evade traditional signature-based defenses. The SOC team should proactively hunt for this behavior in Azure Sentinel to uncover low-severity anomalies that may represent early-stage threats capable of bypassing conventional security controls before they escalate into significant incidents.
rule SkDUndetectabler3NoFSG2MethodSkD
{
meta:
author="malware-lu"
strings:
$a0 = { 55 8B EC 81 EC 10 02 00 00 68 00 02 00 00 8D 85 F8 FD FF FF 50 6A 00 FF 15 38 10 00 01 50 FF 15 3C 10 00 01 8D 8D F8 FD FF FF 51 E8 4F FB FF FF 83 C4 04 8B 15 ?? 16 00 01 52 A1 ?? 16 00 01 50 E8 50 FF FF FF 83 C4 08 A3 ?? 16 00 01 C7 85 F4 FD FF FF 00 00 00 00 EB 0F 8B 8D F4 FD FF FF 83 C1 01 89 8D F4 FD FF FF 8B 95 F4 FD FF FF 3B 15 ?? 16 00 01 73 1C 8B 85 F4 FD FF FF 8B 0D ?? 16 00 01 8D 54 01 07 81 FA 74 10 00 01 75 02 EB 02 EB C7 8B 85 F4 FD FF FF 50 E8 ?? 00 00 00 83 C4 04 89 85 F0 FD FF FF 8B 8D F0 FD FF FF 89 4D FC C7 45 F8 00 00 00 00 EB 09 8B 55 F8 83 C2 01 89 55 F8 8B 45 F8 3B 85 F4 FD FF FF 73 15 8B 4D FC 03 4D F8 8B 15 ?? 16 00 01 03 55 F8 8A 02 88 01 EB D7 83 3D ?? 16 00 01 00 74 }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 4 specific false positive scenarios for the SkDUndetectabler3NoFSG2MethodSkD rule, along with recommended filters and exclusions:
Scenario: Microsoft Defender for Endpoint (MDE) Real-Time Protection Scans
MsMpEng.exe) frequently spawns child processes to scan files in real-time. These scans often utilize the r3 method without explicitly invoking the FSG2 method signature, triggering the rule when scanning large repositories or during scheduled deep scans.C:\Program Files\Microsoft Defender\MsMpEng.exe. Alternatively, apply a filter to exclude alerts where the ParentImage contains “MsMpEng” and the CommandLine includes keywords like “/scan” or “/realtime”.Scenario: Scheduled System Backup Jobs (Veeam or Commvault)
r3 method for rapid file enumeration but may bypass the FSG2 handshake due to high-throughput optimization modes.VeeamTransport.exe or CommServeAgent.exe. If the rule supports hash-based filtering, whitelist the specific SHA256 hashes of these backup agents.Scenario: Endpoint Configuration Management (SCCM/Intune Deployment)
ccmsetup.exe or `DeviceC