This detection identifies adversaries leveraging the specific ocBat2Exe10OC signature to execute or stage malicious binaries that may evade standard heuristic controls. Proactive hunting for this indicator in Azure Sentinel is essential to uncover early-stage lateral movement or command-and-control activities before they escalate into higher-severity incidents.
rule ocBat2Exe10OC
{
meta:
author="malware-lu"
strings:
$a0 = { 55 8B EC B9 08 00 00 00 6A 00 6A 00 49 75 F9 53 56 57 B8 58 3C 40 00 E8 6C FA FF FF 33 C0 55 68 8A 3F 40 00 64 FF 30 64 89 20 6A 00 6A 00 6A 03 6A 00 6A 01 68 00 00 00 80 8D 55 EC 33 C0 E8 81 E9 FF FF 8B 45 EC E8 41 F6 FF FF 50 E8 F3 FA FF FF 8B F8 83 FF FF 0F 84 83 02 00 00 6A 02 6A 00 6A EE 57 E8 FC FA FF FF 6A 00 68 60 99 4F 00 6A 12 68 18 57 40 00 57 E8 E0 FA FF FF 83 3D 60 99 4F 00 12 0F 85 56 02 00 00 8D 45 E4 50 8D 45 E0 BA 18 57 40 00 B9 40 42 0F 00 E8 61 F4 FF FF 8B 45 E0 B9 12 00 00 00 BA 01 00 00 00 E8 3B F6 FF FF 8B 45 E4 8D 55 E8 E8 04 FB [4] E8 B8 58 99 4F 00 E8 67 F3 FF FF 33 C0 A3 60 99 4F 00 8D 45 DC 50 B9 05 00 00 00 BA 01 00 00 00 A1 58 99 4F 00 E8 04 F6 FF FF 8B 45 DC BA A4 3F 40 00 E8 E3 F4 FF FF }
condition:
$a0
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 4 specific false positive scenarios for the ocBat2Exe10OC detection rule, including suggested filters and exclusions:
Scenario: Microsoft Office Click-to-Run Self-Update Execution
officeclicktorun.exe process frequently spawns child processes to handle background updates or license validation. In many enterprise environments, this parent process triggers the YARA rule when it executes a temporary batch file (ocBat2Exe10OC) containing Office-specific logic strings that match the detection signature.C:\Program Files\Microsoft Office Client\OfficeClickToRun.exe and its immediate child processes matching the pattern *\.bat or ocBat2Exe10OC. Alternatively, filter alerts where the command line contains keywords like /update, /install, or OfficeBackgroundTaskHandler.Scenario: Scheduled Antivirus Quarantine Cleanup Job
ocBat2Exe10OC to move files from the quarantine folder to an archive location before deletion, triggering the rule due to the script’s content and execution context.C:\Program Files\CrowdStrike\fsq.exe or C:\Windows\System32\defender.exe) and the scheduled task name contains “Quarantine” or “Cleanup”. A specific filter could target command lines containing /quarantine or paths under C:\ProgramData\<AV_Vendor>\Quarantine.**Scenario: Enterprise Patch Management Deployment