This detection identifies potential file packing or obfuscation activities where null bytes are strategically inserted to evade static analysis and hide malicious payloads within legitimate processes. SOC teams should proactively hunt for this behavior in Azure Sentinel because such packing techniques often indicate early-stage adversary efforts to bypass signature-based defenses, allowing analysts to uncover stealthy threats that traditional antivirus solutions might miss.
rule dePACKdeNULL
{
meta:
author="malware-lu"
strings:
$a0 = { EB 01 DD 60 68 00 [3] 68 [2] 00 00 E8 ?? 00 00 00 }
$a1 = { EB 01 DD 60 68 00 [3] 68 [3] 00 E8 ?? 00 00 00 [128] D2 }
condition:
$a0 at pe.entry_point or $a1 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 2 string patterns in its detection logic.
Here are 4 specific false positive scenarios for the dePACKdeNULL detection rule in an enterprise environment, including suggested filters and exclusions:
Scenario: Scheduled Antivirus Database Updates
C:\Program Files\Microsoft Defender\MsMpEng.exe or C:\ProgramData\CrowdStrike\FalconService.exe when they are executing with a command line containing keywords like “update”, “definition”, or “download”.Scenario: Automated Backup and Archiving Jobs
Veeam.Backup.Service.exe or Commvault Agent service accounts specifically when the process path contains \Backup\ and the file extension is .vbk, .zip, or .tar.Scenario: Software Deployment via Configuration Management