This rule detects the presence of a specific Portable Executable (PE) file that has been encrypted or packed, a common technique used by adversaries to obscure malware payloads and evade static analysis. Proactively hunting for these artifacts in Azure Sentinel allows the SOC team to identify potentially obfuscated binaries on endpoints or in storage, reducing the risk of executing hidden malicious code before it can establish persistence or trigger further compromise.
rule EncryptPEV22006710WFS
{
meta:
author="malware-lu"
strings:
$a0 = { 60 9C 64 FF 35 00 00 00 00 E8 73 01 00 00 }
$a1 = { 60 9C 64 FF 35 00 00 00 00 E8 73 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [8] 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [36] 00 00 00 00 6B 65 72 6E 65 6C 33 32 2E 64 6C 6C 00 00 00 47 65 74 54 65 6D 70 50 61 74 68 41 00 00 00 43 72 65 61 74 65 46 69 6C 65 41 00 00 00 43 72 65 61 74 65 46 69 6C 65 4D 61 70 70 69 6E 67 41 00 00 00 4D 61 70 56 69 65 77 4F 66 46 69 6C 65 00 00 00 55 6E 6D 61 70 56 69 65 77 4F 66 46 69 6C 65 00 00 00 43 6C 6F 73 65 48 61 6E 64 6C 65 00 00 00 4C 6F 61 64 4C 69 62 72 61 72 79 41 00 00 00 47 65 74 50 72 6F 63 41 64 64 72 65 73 73 00 00 00 45 78 69 74 50 72 6F 63 65 73 73 00 00 00 00 }
condition:
$a0 at pe.entry_point or $a1 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 2 string patterns in its detection logic.
cl.exe, link.exe) during automated CI/CD pipeline builds or developer local compilations, where the linker creates new PE executables that match the generic encryption/obfuscation patterns.
msbuild.exe, dotnet.exe, or cl.exe and the file path resides within standard build directories (e.g., C:\builds\, C:\src\, or C:\Users\<dev>\AppData\Local\Temp\).7-Zip (7z.exe) or WinRAR (WinRAR.exe) to extract or compress software packages that contain PE files with specific header structures or compression algorithms that trigger the YARA signature.
7z.exe, WinRAR.exe, or tar.exe and the target file extension is .zip, .7z, .rar, or .tar, or where the file path contains \temp\ or \downloads\ and the file is less than 50MB.MsMpEng.exe for Windows Defender, CrowdStrike Falcon, or CarbonBlack) performing real-time scanning or on-demand scans, where the agent temporarily creates encrypted or packed copies of PE files in memory or temp folders for analysis.
MsMpEng.exe, FalconSensor.exe, cb.exe) and the file path resides in the agent’s specific cache or temp directory (e.g., `C:\Program