This detection identifies potential file-based threats matching the specific FSGv13 signature pattern across Azure Sentinel workloads to uncover early-stage malware or suspicious artifacts. Proactive hunting for this rule is essential because its low severity classification may cause it to be overlooked in standard alerting, requiring manual investigation to prevent silent lateral movement by adversaries leveraging known file signatures.
rule FSGv13
{
meta:
author="malware-lu"
strings:
$a0 = { BB D0 01 40 00 BF 00 10 40 00 BE [4] 53 E8 0A 00 00 00 02 D2 75 05 8A 16 46 12 D2 C3 B2 80 A4 6A 02 5B FF 14 24 73 F7 33 C9 FF 14 24 73 18 33 C0 FF 14 24 73 21 B3 02 41 B0 10 FF 14 24 12 C0 73 F9 75 3F AA EB DC E8 43 00 00 00 2B CB 75 10 E8 38 00 }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 5 specific false positive scenarios for the FSGv13 detection rule, including suggested filters and exclusions tailored for an enterprise environment:
Scenario: Legitimate deployment of security patches via Microsoft Endpoint Configuration Manager (SCCM) or Intune.
ccmexec.exe process launches a child process to download or install updates, mimicking the behavior pattern FSGv13 is designed to catch.C:\Program Files\Microsoft Intune Management Extension\IntuneManagementExtensionService.exe or C:\Windows\CCM\ccmexec.exe. Additionally, add a filter for file hashes known to be signed by “Microsoft Corporation” with a valid timestamp.Scenario: Scheduled antivirus scanning jobs running as a background service (e.g., Microsoft Defender Antivirus).
MsMpEng.exe process scans user directories and may spawn temporary worker processes that match the FSGv13 signature logic.MsMpEng.exe. Furthermore, implement a time-based filter to suppress alerts generated between 02:00 and 04:00 local time when scheduled scans typically occur.Scenario: Execution of automated backup scripts using enterprise tools like Veeam or Commvault.
VeeamTransportService.exe or CommServe.exe.