This YARA rule targets a specific, low-severity build of the tElock ransomware variant, indicating the presence of a known malicious binary that may be used for initial access or lateral movement. Proactively hunting for this signature allows the SOC team to identify dormant or early-stage infections in Azure Sentinel before the ransomware can encrypt data or establish persistence.
rule tElockv099SpecialBuildheXerforgot
{
meta:
author="malware-lu"
strings:
$a0 = { E9 5E DF FF FF 00 00 00 [4] E5 [2] 00 00 00 00 00 00 00 00 00 05 [2] 00 F5 [2] 00 ED [2] 00 00 00 00 00 00 00 00 00 12 [2] 00 FD [2] 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1D [2] 00 00 00 00 00 30 [2] 00 00 }
$a1 = { E9 5E DF FF FF 00 00 00 [4] E5 [2] 00 00 00 00 00 00 00 00 00 05 [2] 00 F5 [2] 00 ED [2] 00 00 00 00 00 00 00 00 00 12 [2] 00 FD [2] 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1D [2] 00 00 00 00 00 30 [2] 00 00 00 00 00 1D [2] 00 00 00 00 00 30 [2] 00 00 00 00 00 }
condition:
$a0 at pe.entry_point or $a1 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 2 string patterns in its detection logic.
Legitimate Custom Build Deployment: A DevOps team deploys a custom-compiled version of a proprietary internal tool (e.g., internal-config-sync.exe) that was built with a specific compiler flag or linker version matching the YARA signature. This often happens when a developer forgets to strip debug symbols or uses a non-standard build pipeline for a “special build” of an internal utility.
C:\Apps\InternalTools\) or exclude processes where the parent is a known deployment agent (e.g., Ansible, Chef, or Puppet) and the file hash matches a known good baseline.Antivirus/EDR Quarantine Scan: An endpoint protection platform (e.g., CrowdStrike, Defender for Endpoint) performs a deep scan or quarantine operation on a large number of files, temporarily loading them into memory or creating temporary copies that match the YARA pattern due to the “special build” metadata embedded in the file header.
MsMpEng.exe, CrowdStrike.exe, SentinelOne.exe) and the action is “Scan” or “Quarantine” rather than “Execute” or “Create”.Scheduled Backup Job: A scheduled backup job (e.g., Veeam, Commvault, or Windows Server Backup) creates temporary snapshot files or deduplication chunks that inherit the metadata or structure of the source files. If the source file is a “special build,” the temporary backup artifact may trigger the YARA rule during the write phase.
VeeamBackup.exe, `CommvaultAgent.exe