This detection identifies potentially malicious executables exhibiting stealthy code signing anomalies that may indicate an adversary attempting to bypass trust mechanisms through pseudo-signing techniques. Proactively hunting for these signatures in Azure Sentinel is essential to uncover early-stage supply chain compromises or fileless attacks that evade standard signature-based defenses by mimicking legitimate software behavior.
rule PseudoSigner01StelthPE101Anorganix
{
meta:
author="malware-lu"
strings:
$a0 = { 0B C0 0B C0 0B C0 0B C0 0B C0 0B C0 0B C0 0B C0 BA [4] FF E2 BA E0 10 40 00 B8 68 24 1A 40 89 02 83 C2 03 B8 40 00 E8 EE 89 02 83 C2 FD FF E2 2D 3D 5B 20 48 69 64 65 50 45 20 5D 3D 2D 90 00 00 00 }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 5 specific false positive scenarios for the PseudoSigner01StelthPE101Anorganix detection rule, along with suggested filters and exclusions:
Scenario: Microsoft Office Click-to-Run Self-Update Mechanism
OfficeClickToRun.exe process frequently generates temporary PE files in the %ProgramFiles%\Microsoft Office\root\Office16\ directory during background updates. These temporary binaries often lack full digital signatures or use internal pseudo-signatures that trigger the YARA rule’s “Anorganix” logic due to non-standard header structures.ProcessName equals OfficeClickToRun.exe AND FilePath starts with C:\Program Files\Microsoft Office\root\.Scenario: Antivirus Real-Time Scanning of Staged Installers
\Temp\ or \AppData\Local\Microsoft\Windows\Temporary Internet Files\ when the parent process is FalconService.exe (CrowdStrike) or SoneAgent.exe (SentinelOne).Scenario: Scheduled PowerShell Script Execution via Task Scheduler
.ps1 scripts which dynamically generate temporary executables for reporting or data aggregation. These scripts frequently invoke the .NET runtime to compile