This rule identifies potentially obfuscated or packed Windows executables that may be used by adversaries to hide malicious code from static analysis. Proactively hunting for these artifacts helps the SOC team detect low-severity threats that could serve as initial access vectors or persistence mechanisms before they execute in the environment.
rule EncryptPEV22007411WFS
{
meta:
author="malware-lu"
strings:
$a0 = { 60 9C 64 FF 35 00 00 00 00 E8 1B 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [8] 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [36] 00 00 00 00 6B 65 72 6E 65 6C 33 32 2E 64 6C 6C 00 00 00 47 65 74 54 65 6D 70 50 61 74 68 41 00 00 00 43 72 65 61 74 65 46 69 6C 65 41 00 00 00 43 72 65 61 74 65 46 69 6C 65 4D 61 70 70 69 6E 67 41 00 00 00 4D 61 70 56 69 65 77 4F 66 46 69 6C 65 00 00 00 55 6E 6D 61 70 56 69 65 77 4F 66 46 69 6C 65 00 00 00 43 6C 6F 73 65 48 61 6E 64 6C 65 00 00 00 4C 6F 61 64 4C 69 62 72 61 72 79 41 00 00 00 47 65 74 50 72 6F 63 41 64 64 72 65 73 73 00 00 00 45 78 69 74 50 72 6F 63 65 73 73 00 00 00 00 00 00 }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Scenario: A developer or DevOps engineer uses 7-Zip (or WinRAR) to compress a large source code repository or build artifact into a .zip or .7z archive. The YARA rule may match the specific header bytes or entropy patterns of the compressed executable files within the archive, especially if the compression algorithm results in high entropy that mimics encryption.
7z.exe, 7zG.exe, WinRAR.exe, or WinRAR.exe and the file extension is .zip, .7z, or .rar. Additionally, exclude files located in standard build directories like C:\Builds\ or C:\Artifacts\.Scenario: An IT administrator runs Veeam Backup & Replication or Commvault backup agents on a server. These tools often encrypt backup blocks or use high-entropy compression for data chunks. If the YARA rule scans memory or temporary files created during the backup process, it may flag the encrypted/obfuscated data blocks as malicious.
VeeamBackup.exe, VeeamBackupService.exe, commvaultagent.exe, or cvagent.exe. Also, exclude file paths containing \Veeam\, \Commvault\, or \Backup\.Scenario: A system administrator uses BitLocker management tools or PowerShell (Enable-BitLocker cmdlet) to encrypt a drive. During the encryption process, temporary files or memory regions may exhibit characteristics that match the “EncryptPE” signature, particularly if the rule is sensitive to high-entropy PE headers or specific encryption algorithm identifiers.
powershell.exe or pwsh.exe when the command