This hypothesis targets the execution of the YodasProtector malware family, a known threat that often leverages specific memory patterns or code structures to establish persistence or perform data exfiltration. Proactively hunting for this signature in Azure Sentinel allows the SOC to identify compromised endpoints early, preventing potential lateral movement or privilege escalation before the low-severity indicator escalates into a more impactful breach.
rule yodasProtector102AshkibizDanehlar
{
meta:
author="malware-lu"
strings:
$a0 = { E8 03 00 00 00 EB 01 ?? BB 55 00 00 00 E8 03 00 00 00 EB 01 ?? E8 8F 00 00 00 E8 03 00 00 00 EB 01 ?? E8 82 00 00 00 E8 03 00 00 00 EB 01 ?? E8 B8 00 00 00 E8 03 00 00 00 EB 01 ?? E8 AB 00 00 00 E8 03 00 00 00 EB 01 ?? 83 FB 55 E8 03 00 00 00 EB 01 ?? 75 }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
MSBuild or a custom Go binary) that includes specific string constants or byte sequences matching the yodasProtector102 signature due to shared library linking or hardcoded configuration strings.
C:\Users\*\AppData\Local\Temp, C:\Projects\, C:\BuildAgents\) and exclude processes initiated by known build service accounts (e.g., svc-build, jenkins-agent).FalconSensor.exe, cb.exe, sentinelone.exe) and the file path resides in the EDR’s temporary scan directory (e.g., C:\ProgramData\CrowdStrike\, C:\ProgramData\CarbonBlack\).vcredist_x64.exe from a specific vendor or a custom logcollector.exe) that was compiled with a linker or compression algorithm that inadvertently matches the YARA signature.
*collector*.exe, `diag.