This hunt hypothesis targets adversary behavior involving the execution of custom or obfuscated binaries that evade standard detection mechanisms during scan time windows, as identified by the specific YARA signature STUDRC410JamieEditionScanTimeUnDetectablebyMarjinZ. A SOC team should proactively hunt for this activity in Azure Sentinel to uncover stealthy threats that bypass conventional security controls and potentially establish persistence before triggering higher-severity alerts.
rule STUDRC410JamieEditionScanTimeUnDetectablebyMarjinZ
{
meta:
author="malware-lu"
strings:
$a0 = { 68 2C 11 40 00 E8 F0 FF FF FF 00 00 00 00 00 00 30 00 00 00 38 00 00 00 00 00 00 00 37 BB 71 EC A4 E1 98 4C 9B FE 8F 0F FA 6A 07 F6 00 00 00 00 00 00 01 00 00 00 20 20 46 6F 72 20 73 74 75 64 00 20 54 6F 00 00 00 00 06 00 00 00 CC 1A 40 00 07 00 00 00 D4 18 40 00 07 00 00 00 7C 18 40 00 07 00 00 00 2C 18 40 00 07 00 00 00 E0 17 40 00 56 42 35 21 F0 1F 2A 00 00 00 00 00 00 00 00 00 00 00 00 00 7E 00 00 00 00 00 00 00 00 00 00 00 00 00 0A 00 09 04 00 00 00 00 00 00 E8 13 40 00 F4 13 40 00 00 F0 30 00 00 FF FF FF 08 00 00 00 01 00 00 00 00 00 00 00 E9 00 00 00 04 11 40 00 04 11 40 00 C8 10 40 00 78 00 00 00 7C 00 00 00 81 00 00 00 82 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 61 61 61 00 53 74 75 64 00 00 73 74 75 64 00 00 01 00 01 00 30 16 40 00 00 00 00 00 FF FF FF FF FF FF FF FF 00 00 00 00 B4 16 40 00 10 30 40 00 07 00 00 00 24 12 40 00 0E 00 20 00 00 00 00 00 1C 9E 21 00 EC 11 40 00 5C 10 40 00 E4 1A 40 00 2C 34 40 00 68 17 40 00 58 17 40 00 78 17 40 00 8C 17 40 00 8C 10 40 00 62 10 40 00 92 10 40 00 F8 1A 40 00 24 19 40 00 98 10 40 00 9E 10 40 00 77 04 18 FF 04 1C FF 05 00 00 24 01 00 0D 14 00 78 1C 40 00 48 21 40 00 }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 5 specific false positive scenarios for the detection rule STUDRC410JamieEditionScanTimeUnDetectablebyMarjinZ, along with recommended filters and exclusions:
Scenario: Scheduled Antivirus Deep Scan by CrowdStrike Falcon
C:\Users\Public directory where the YARA rule monitors file access patterns. During this window, the scanner accesses thousands of files in rapid succession, mimicking the behavior of an un-detectable scan time anomaly.falcon.sys or FalconSensor.exe when the source directory is C:\Users\Public. Alternatively, add a time-based exclusion window (02:00–04:00 UTC) for this specific rule.Scenario: Microsoft Defender for Endpoint Real-Time Protection Scan
C:\Users\<User>\OneDrive). The high volume of file I/O triggers the “un-detectable scan time” logic as files are opened and closed faster than the rule’s threshold expects.MsMpEng.exe (Microsoft Defender) where the monitored path contains \OneDrive\. Additionally, configure an exclusion in the detection logic to ignore events with a scan duration under 50ms for this specific process.Scenario: Automated Backup Job by Veeam Agent