This YARA rule targets specific memory artifacts associated with the Armadillov420SiliconRealmsToolworks tool, indicating the presence of a low-severity utility or script often used for initial access or post-exploitation tasks. Proactively hunting for this signature allows the SOC team to identify dormant or stealthy tooling in Azure environments before it is leveraged for lateral movement or data exfiltration.
rule Armadillov420SiliconRealmsToolworks
{
meta:
author="malware-lu"
strings:
$a0 = { 55 8B EC 6A FF 68 F8 8E 4C 00 68 F0 EA 49 00 64 A1 00 00 00 00 50 64 89 25 00 00 00 00 83 EC 58 53 56 57 89 65 E8 FF 15 88 31 4C 00 33 D2 8A D4 89 15 84 A5 4C 00 8B C8 81 E1 FF 00 00 00 89 0D 80 A5 4C 00 C1 E1 08 03 CA 89 0D 7C A5 4C 00 C1 E8 10 A3 78 A5 }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
terraform CLI on a build agent to provision cloud infrastructure, where the binary or its associated helper scripts contain string patterns matching the YARA rule’s generic memory or file signatures.
terraform.exe or terraform.exe is running from a known CI/CD directory (e.g., C:\Jenkins\workspace\ or D:\AzurePipelines\).7z.exe (7-Zip) to extract a large software bundle on a jump server, where the compression library’s internal string tables or metadata trigger the detection due to overlapping hex patterns.
\7-Zip\ or process names 7z.exe, 7zG.exe, and 7zFM.exe when the user belongs to the IT_Admins security group.python.exe to execute a custom log rotation script in C:\Scripts\maintenance\, where the Python interpreter’s memory layout or embedded bytecode strings match the YARA rule’s byte or string conditions.
python.exe or python3.exe processes where the command line contains rotate_logs.py or the working directory is C:\Scripts\maintenance\.nmap.exe or masscan.exe) performs a port scan from a dedicated scanning host, where the tool’s binary contains specific protocol string constants that inadvertently match the YARA rule’s ascii or wide string conditions.
nmap.exe, masscan.exe, or `zmap.exe