This detection identifies potentially malicious or suspicious executables that utilize a specific pseudo-signing pattern often associated with the Anorganix family, which may indicate an adversary attempting to bypass signature-based defenses through deceptive code signing. A proactive hunt is essential within Azure Sentinel to uncover early-stage lateral movement or initial access attempts where attackers leverage these nuanced signing artifacts to evade standard security controls before establishing persistence.
rule PseudoSigner01Anorganix
{
meta:
author="malware-lu"
strings:
$a0 = { 90 90 90 90 68 [4] 67 64 FF 36 00 00 67 64 89 26 00 00 F1 90 90 90 90 }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 4 specific false positive scenarios for the PseudoSigner01Anorganix detection rule in an enterprise environment, along with suggested filters and exclusions:
Scenario: Scheduled Antivirus Definition Updates via Microsoft Defender
PseudoSigner01Anorganix rule. This occurs when the MsMpEng.exe service downloads and applies new virus definition signatures, creating temporary artifacts that match the YARA pattern.C:\Program Files\Microsoft Defender\MsMpEng.exe. Alternatively, filter alerts where the parent process is MsMpEng.exe or the command line contains /update.Scenario: Automated Patch Deployment via SCCM (System Center Configuration Manager)
ccmexec.exe) executes software updates and patches. When deploying specific .NET-based applications or runtime libraries, the installation process generates signed binaries that trigger this rule due to overlapping cryptographic hash structures in the pseudo-signer logic.ccmexec.exe. Additionally, exclude alerts occurring during defined maintenance windows (e.g., 02:00–04:00 UTC) where the user context is NT SERVICE\CCMService.Scenario: CI/CD Pipeline Artifact Signing by Azure DevOps
msbuild.exe or vstest.console.exe) frequently signs build artifacts before pushing them to the repository. The signing tool used in the pipeline often utilizes a certificate structure that aligns with the `P