This hypothesis posits that adversaries are utilizing specific file artifacts identified by the WhiskeyCharlie YARA signature to establish persistence or execute initial reconnaissance within the environment. The SOC team should proactively hunt for these indicators in Azure Sentinel to validate the rule’s low-severity alerts against actual threat activity, ensuring early detection of potential lateral movement before it escalates into a critical incident.
rule WhiskeyCharlie
{
meta:
copyright = "2015 Novetta Solutions"
author = "Novetta Threat Research & Interdiction Group - trig@novetta.com"
Source = "47ff4f73738acc2f8433dccb2caf980d7444d723ccf2968d69f88f8f96405f96"
strings:
/*
66 89 55 DC mov [ebp+SystemTime.wYear], dx
E8 1E 16 00 00 call _rand
6A 0C push 0Ch
99 cdq
59 pop ecx
F7 F9 idiv ecx
42 inc edx
66 89 55 DE mov [ebp+SystemTime.wMonth], dx
E8 0E 16 00 00 call _rand
6A 1C push 1Ch
99 cdq
59 pop ecx
F7 F9 idiv ecx
42 inc edx
66 89 55 E2 mov [ebp+SystemTime.wDay], dx
E8 FE 15 00 00 call _rand
6A 18 push 18h
99 cdq
59 pop ecx
F7 F9 idiv ecx
66 89 55 E4 mov [ebp+SystemTime.wHour], dx
E8 EF 15 00 00 call _rand
6A 3C push 3Ch
99 cdq
59 pop ecx
F7 F9 idiv ecx
66 89 55 E6 mov [ebp+SystemTime.wMinute], dx
E8 E0 15 00 00 call _rand
6A 3C push 3Ch
99 cdq
59 pop ecx
F7 F9 idiv ecx
*/
$a = {66 89 55 DC E8 [4] 6A 0C 99 59 F7 F9 42 66 89 55 DE E8 [4] 6A 1C 99 59 F7 F9 42 66 89 55 E2 E8 [4] 6A 18 99 59 F7 F9 66 89 55 E4 E8 [4] 6A 3C 99 59 F7 F9 66 89 55 E6 E8 [4] 6A 3C 99 59 F7 F9 }
condition:
$a in ((pe.sections[pe.section_index(".text")].raw_data_offset)..(pe.sections[pe.section_index(".text")].raw_data_offset + pe.sections[pe.section_index(".text")].raw_data_size))
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 4 specific false positive scenarios for the WhiskeyCharlie YARA detection rule in an enterprise environment, including suggested filters and exclusions:
Antivirus Real-Time Scanning on Large Archives
.zip or .tar.gz archives containing thousands of files. During this extraction and scanning phase, the agent’s worker process may exhibit memory patterns or file hash sequences that match the WhiskeyCharlie signature, particularly if the rule looks for specific entropy changes in temporary directories.C:\Program Files\CrowdStrike\csagent.exe, C:\Windows\System32\MsMpEng.exe) when accessing paths within %TEMP% or dedicated scan queues. Additionally, filter alerts where the parent process is the EDR service itself and the file extension is .zip, .7z, or .gz.Scheduled Software Distribution via SCCM/Intune
C:\Windows\CCMCache) before execution. The rapid creation of temporary files and the specific command-line arguments used by ccmexec.exe or Win32_OptimizationService can trigger the YARA rule if it detects known legitimate deployment signatures as anomalies.