This detection identifies potential file-based threats matching the specific signature defined by the FSGv12 YARA rule, which may indicate early-stage adversary activity or known malware variants within the environment. Proactively hunting for this indicator in Azure Sentinel allows the SOC team to validate low-severity alerts against broader context, ensuring that subtle file anomalies are not overlooked before they escalate into significant incidents.
rule FSGv12
{
meta:
author="malware-lu"
strings:
$a0 = { 4B 45 52 4E 45 4C 33 32 2E 64 6C 6C 00 00 4C 6F 61 64 4C 69 62 72 61 72 79 41 00 00 47 65 74 50 72 6F 63 41 64 64 72 65 73 73 00 ?? 00 00 00 00 00 }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 4 specific false positive scenarios for the FSGv12 detection rule, including context and suggested exclusions:
Antivirus Engine Signature Updates
C:\Program Files\CrowdStrike\FalconSensor\CSFalconService.exe) or filter out file paths containing \Updates\ and \Definitions\.Microsoft Office 365 Click-to-Run Deployment
.cab or .msi packages and launching temporary installers (setup.exe, officec2rclient.exe) which mimic the behavior of a staged fileless attack detected by FSGv12.OfficeClickToRun.exe and any child processes spawned under the path C:\Program Files\Microsoft Office Root\Office16.Scheduled System Backup Jobs (Veeam/Azure)
veeamagent.exe