This rule identifies executable files compiled with Borland Delphi 5.0 that exhibit specific structural markers associated with the PseudoSigner tool, a technique often used by adversaries to create fake digital signatures to bypass security controls. Proactively hunting for these artifacts in Azure Sentinel helps detect potentially malicious or unsigned binaries that may be leveraging outdated compiler signatures to evade detection and establish a foothold within the environment.
rule _PseudoSigner_01_Borland_Delphi_50_KOLMCK_Anorganix: PEiD
{
strings:
$a = { 55 8B EC 90 90 90 90 68 ?? ?? ?? ?? 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 00 FF 90 90 90 90 90 90 90 90 00 01 90 90 90 90 90 90 90 90 90 EB 04 00 00 00 01 90 90 90 90 90 90 90 00 01 90 90 90 90 90 90 90 90 90 }
condition:
$a at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
C:\Program Files\InternalApps\HRSystem\) or exclude based on the specific file hash if the binary is static. Additionally, consider whitelisting the parent process if the executable is launched by a known service host like svchost.exe or a specific app launcher.cmd.exe, powershell.exe, wmic.exe) and the file path contains keywords like temp, tools, or utilities. Alternatively, exclude if the file’s digital signature issuer matches a known legacy vendor list.schtasks.exe or TaskScheduler and resides