This hunt hypothesis targets adversaries utilizing the EXE32Pack v136 packing technique to obfuscate executable files and evade signature-based detection. A SOC team should proactively hunt for this behavior in Azure Sentinel because packed executables often conceal malicious payloads that may bypass initial scanning, requiring deeper behavioral analysis to identify potential threats before they execute.
rule EXE32Packv136
{
meta:
author="malware-lu"
strings:
$a0 = { 3B C0 74 02 81 83 55 3B C0 74 02 81 83 53 3B C9 74 01 BC [4] 02 81 [7] 3B DB 74 01 BE 5D 8B D5 81 ED CC 8D 40 }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 4 specific false positive scenarios for the EXE32Packv136 detection rule, along with targeted filtering strategies:
Scenario: Microsoft Office Click-to-Run Updates
OfficeC2RClient.exe or Setup.exe) frequently utilizes the EXE32 packer for its update modules. When scheduled updates run during business hours, they often trigger this rule as they unpack and execute new components.\Microsoft Office ClickToRun\ or filter specifically for OfficeC2RClient.exe where the parent process is MsMpEng.exe (Windows Defender) or System.Scenario: Enterprise Antivirus Real-Time Scanning
ImageName matches known security vendor binaries (e.g., FalconSensor.exe, SoneAgent.exe) and the parent process is a trusted service manager like svchost.exe.Scenario: Scheduled Deployment via SCCM or Intune