This detection identifies silent software installations by STProtector V15, a behavior often indicative of adversaries establishing persistence or deploying custom tools without triggering standard user notifications. Proactively hunting for this activity in Azure Sentinel allows the SOC team to uncover stealthy initial access or lateral movement attempts that might otherwise remain invisible due to their non-intrusive nature.
rule STProtectorV15SilentSoftware
{
meta:
author="malware-lu"
strings:
$a0 = { 00 00 00 00 4B 65 52 6E 45 6C 33 32 2E 64 4C 6C 00 00 47 65 74 50 72 6F 63 41 64 64 72 65 73 73 00 00 4C 6F 61 64 4C 69 62 72 61 72 79 41 00 00 }
condition:
$a0
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 4 specific false positive scenarios for the STProtectorV15SilentSoftware detection rule, including targeted filters and exclusions:
Scenario: Microsoft Office Click-to-Run Silent Updates
OfficeClickToRun.exe process often executes a silent update mechanism that mimics the behavior of STProtector’s installation logic. This frequently occurs during off-hours or when users launch an Office application for the first time after a patch cycle.C:\Program Files\Microsoft Office Root\Office16 and the command line arguments include /quiet or update.Scenario: SCCM (ConfigMgr) Application Deployment
ccmsetup.exe or installutil.exe process invokes the STProtector signature logic to ensure compliance before installation.ccmexec.exe or wuauserv.exe (Windows Update) that are running under the context of a scheduled task with names containing “SoftwareUpdate” or “AppDeployment”.Scenario: Antivirus Real-Time Protection Scanning
AppData\Local\Temp directory.%TEMP% directories and the process image hash matches known signatures for CrowdStrike (`csf