This hypothesis targets the presence of the SDProtect RandyLi YARA signature, which indicates the execution or memory footprint of a specific low-severity malware variant or tooling component. Proactively hunting for this indicator allows the SOC team to identify dormant or stealthy implants in Azure Sentinel that may have bypassed initial perimeter defenses, ensuring early detection of potential lateral movement or data staging activities.
rule SDProtectRandyLi
{
meta:
author="malware-lu"
strings:
$a0 = { 55 8B EC 6A FF 68 [4] 68 88 88 88 08 64 A1 00 00 00 00 50 64 89 25 00 00 00 00 58 64 A3 00 00 00 00 58 58 58 58 8B E8 E8 3B 00 00 00 E8 01 00 00 00 FF 58 05 }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
sdprotect utility (or a similar custom internal tool named SDProtectRandyLi) to encrypt/decrypt sensitive configuration files or API keys during a local build or staging deployment.
msbuild.exe, dotnet.exe, npm.exe) or where the working directory is under a standard development path (e.g., C:\Users\<dev>\projects\, C:\builds\).SDProtectRandyLi.exe to rotate secrets in a local vault or update license keys for enterprise software (e.g., Adobe Creative Cloud, Autodesk, or Oracle clients).
Task Scheduler (taskschd.msi or svchost.exe with specific service GUIDs) or where the command line contains keywords like rotate, update-license, or sync.SDProtectRandyLi from a command prompt to troubleshoot or re-protect a corrupted security descriptor on a file share or registry key during an ADFS or DNS zone maintenance window.
Domain Admins, IT-Admins) and the process is launched from an interactive desktop session (not a service) with a short runtime (< 30 seconds).