This detection identifies potential malicious activity associated with the “BladeJoinerv15” signature, which may indicate an adversary leveraging specific code patterns to establish a foothold or execute initial payload delivery within the environment. The SOC team should proactively hunt for this indicator in Azure Sentinel to validate its benign nature and rule out early-stage compromise attempts that could evolve into more severe threats if left unaddressed.
rule BladeJoinerv15
{
meta:
author="malware-lu"
strings:
$a0 = { 55 8B EC 81 C4 E4 FE FF FF 53 56 57 33 C0 89 45 F0 89 85 }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 4 specific false positive scenarios for the BladeJoinerv15 detection rule, tailored for a legitimate enterprise environment:
Scenario: Scheduled Endpoint Protection Scans
BladeJoiner when it is invoked during automated daily scans by Microsoft Defender Antivirus or CrowdStrike Falcon. These tools often spawn child processes that load similar memory modules to analyze file integrity, mimicking the behavior of the targeted tool.MsMpEng.exe, C-Drive\Program Files\CrowdStrike\FalconSensor\csfalcon.exe) when they spawn child processes matching the BladeJoiner hash. Alternatively, exclude alerts where the parent process is known security software and the event time falls within the defined maintenance window (e.g., 02:00–04:00).Scenario: Automated Patch Deployment via SCCM/Intune
BladeJoiner to merge configuration files or join database shards. The rule triggers because the tool runs as a scheduled task under the SYSTEM account rather than an interactive user session.NT AUTHORITY\SYSTEM and the command line arguments contain specific deployment flags (e.g., /deploy, /merge). Add these specific SCCM/Intune task sequences to a whitelist of trusted scheduled jobs.Scenario: Legacy Backup Job Execution