This hypothesis targets the presence of executables packed with ASProtect v11, a technique frequently employed by adversaries to obfuscate malware payloads and evade static analysis. Proactively hunting for these files in Azure Sentinel allows the SOC team to identify suspicious binaries that may be hiding malicious logic, thereby reducing the risk of undetected compromise through common packing mechanisms.
rule ASProtectv11
{
meta:
author="malware-lu"
strings:
$a0 = { 60 E9 ?? 04 [2] E9 [7] EE }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
C:\Program Files\ or C:\Windows\System32\drivers\ and trigger the rule during routine patching or software installation.
C:\Program Files\, C:\Program Files (x86)\) that have a valid digital signature from a known vendor (e.g., Microsoft, Oracle, SAP) and were modified within the last 30 days.setup.exe or install.exe from temporary folders or vendor-specific directories during scheduled maintenance windows.
C:\Windows\Temp\ or vendor-specific temp directories (e.g., C:\Intel\, C:\AMD\) that are child processes of known installer executables (e.g., msiexec.exe, setup.exe) and have a valid digital signature.C:\Program Files\Kaspersky\, C:\Program Files\Symantec\) that are owned by a trusted