This detection identifies potential file obfuscation or packing activities via the UnnamedScrambler10p0ke YARA signature, which adversaries often employ to hide malicious payloads from static analysis tools. SOC teams should proactively hunt for this behavior in Azure Sentinel to uncover stealthy threats that may evade traditional antivirus solutions by masking their true code structure during initial execution phases.
rule UnnamedScrambler10p0ke
{
meta:
author="malware-lu"
strings:
$a0 = { 55 8B EC 83 C4 EC 53 56 33 C0 89 45 [4] 40 00 E8 11 F4 FF FF BE 30 6B 40 00 33 C0 55 68 C9 42 40 00 64 FF 30 64 89 20 E8 C9 FA FF FF BA D8 42 40 00 8B [4] FF FF 8B D8 B8 28 6B 40 00 8B 16 E8 37 F0 FF FF B8 2C 6B 40 00 8B 16 E8 2B F0 FF FF B8 28 6B 40 00 E8 19 F0 FF FF 8B D0 8B C3 8B 0E E8 42 E3 FF FF BA DC 42 40 00 8B C6 E8 2A FA FF FF 8B D8 B8 20 6B 40 00 8B 16 E8 FC EF FF FF B8 24 6B 40 00 8B 16 E8 F0 EF FF FF B8 20 6B 40 00 E8 DE EF FF FF 8B D0 8B C3 8B 0E E8 07 E3 FF FF 6A 00 6A 19 6A 00 6A 32 A1 28 6B 40 00 E8 59 EF FF FF 83 E8 05 03 C0 8D 55 EC E8 94 FE FF FF 8B 55 EC B9 24 6B 40 00 A1 20 6B 40 00 E8 E2 F6 FF FF 6A 00 6A 19 6A 00 6A 32 }
condition:
$a0
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 4 specific false positive scenarios for the UnnamedScrambler10p0ke YARA rule, including suggested filters and exclusions:
Scenario: Scheduled Antivirus Definition Updates
C:\Program Files\Microsoft Security Client\MsMpEng.exe (Defender) or C:\ProgramData\CrowdStrike\FalconSensor\bin\csfalcon.exe. Additionally, filter alerts occurring between 02:30 and 04:00 on workstations where the process parent is a known system scheduler service (svchost.exe running as System).Scenario: Automated Software Deployment via SCCM/Intune
ccmsetup.exe (SCCM) or Microsoft.IntuneManagementService.exe. Implement a logic filter to suppress alerts where the file path contains \AppData\Local\Temp\ and the process tree depth is less than 3 levels, indicating a transient staging operation rather than user-initiated execution.Scenario: Backup Agent Data Compression Jobs