This rule targets the execution of the Yodas Protector, a lightweight process hollowing and injection tool often used by adversaries to hide malicious code within legitimate processes. Proactively hunting for this indicator in Azure Sentinel allows the SOC to identify early-stage post-exploitation activity that may evade traditional signature-based detections.
rule yodasProtectorV1032AshkbizDanehkar
{
meta:
author="malware-lu"
strings:
$a0 = { E8 03 00 00 00 EB 01 ?? BB 55 00 00 00 E8 03 00 00 00 EB 01 ?? E8 8F 00 00 00 E8 03 00 00 00 EB 01 ?? E8 82 00 00 00 E8 03 00 00 00 EB 01 ?? E8 B8 00 00 00 E8 03 00 00 00 EB 01 ?? E8 AB 00 00 00 E8 03 00 00 00 EB 01 ?? 83 FB 55 E8 03 00 00 00 EB 01 ?? 75 2E E8 03 00 00 00 EB 01 ?? C3 60 E8 00 00 00 00 5D 81 ED 94 73 42 00 8B D5 81 C2 E3 73 42 00 52 E8 01 00 00 00 C3 C3 E8 03 00 00 00 EB 01 ?? E8 0E 00 00 00 E8 D1 FF FF FF C3 E8 03 00 00 00 EB 01 ?? 33 C0 64 FF 30 64 89 20 CC C3 E8 03 00 00 00 EB 01 ?? 33 C0 64 FF 30 64 89 20 4B CC C3 E8 03 00 00 00 EB 01 ?? 33 DB B9 BF A4 42 00 81 E9 8E 74 42 00 8B D5 81 C2 8E 74 42 00 8D 3A 8B F7 33 C0 E8 03 00 00 00 EB 01 ?? E8 17 00 00 00 90 90 90 E9 63 29 00 00 33 C0 64 FF 30 64 89 20 43 CC C3 }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
C:\Program Files\InternalTools\) or allowlist specific executable names (e.g., InventoryManager.exe) if the application version is known to use this packer.C:\Windows\Installer\, C:\ProgramData\Package Cache\) or allowlist specific parent processes known to launch installers (e.g., msiexec.exe, setup.exe from known vendor paths).C:\Users\<user>\source\repos\, C:\dev\builds\) or allowlist processes spawned by IDEs or build tools (e.g., dotnet.exe, `msbuild.exe