This detection identifies potential malicious activity associated with the ASPack v212 packer signature identified by Alexey Solodovnikov, which often indicates obfuscated executables used to conceal malware or suspicious payloads within the environment. Proactively hunting for this behavior in Azure Sentinel is essential because low-severity detections of known packing tools can serve as early indicators of sophisticated evasion techniques that might otherwise be overlooked until a broader incident occurs.
rule ASPackv212AlexeySolodovnikov
{
meta:
author="malware-lu"
strings:
$a0 = { 60 E8 03 00 00 00 E9 EB 04 5D 45 55 C3 E8 01 }
$a1 = { 60 E8 03 00 00 00 E9 EB 04 5D 45 55 C3 E8 01 00 00 00 EB 5D BB ED FF FF FF 03 DD 81 EB }
condition:
$a0 at pe.entry_point or $a1 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 2 string patterns in its detection logic.
Here are 4 specific false positive scenarios for the ASPackv212AlexeySolodovnikov YARA rule, which typically detects ASPack-packed executables often associated with malware obfuscation:
Scenario: Deployment of Patched Enterprise Applications via SCCM/Intune
EXCLUSION_PATH: C:\Program Files\Microsoft Configuration Manager\AdminConsole\EXCLUSION_PATH: C:\Windows\CCM\Scenario: Scheduled Backup Agent Execution
FILTER_CONDITION: ProcessName IN ('VeeamAgent.exe', 'AcronisBackupService.exe') AND TimeWindow BETWEEN 01:00 AND 05:00C:\Program Files\Veeam\...).Scenario: Execution of Internal DevOps Build Artifacts