This detection identifies potentially malicious 32-bit executable files packed with a specific v137 compression technique that often obscures internal code structures to evade static analysis. A proactive hunt in Azure Sentinel is essential because these packed binaries frequently serve as initial access vectors or living-off-the-land tools, requiring dynamic inspection to uncover hidden payloads before they execute within the environment.
rule EXE32Packv137
{
meta:
author="malware-lu"
strings:
$a0 = { 3B C0 74 02 81 83 55 3B C0 74 02 81 83 53 3B C9 74 01 BC [4] 02 81 [7] 3B DB 74 01 BE 5D 8B D5 81 ED 4C 8E 40 }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 5 specific false positive scenarios for the EXE32Packv137 detection rule, including context and recommended filters:
Scenario: Legitimate deployment of Microsoft Office updates via the Click-to-Run installer.
OfficeClickToRun.exe process often utilizes the 32-bit packaging engine (EXE32Pack) to stage and install cumulative updates in the background, triggering the rule during peak business hours.Process Name equals OfficeClickToRun.exe AND File Path contains \Microsoft Office\.Scenario: Execution of scheduled antivirus definition updates by CrowdStrike Falcon or Symantec Endpoint Protection.
Process Name containing FalconSensor.exe, Symantec.exe, or rtvscan.exe when the parent process is TaskScheduler.exe.Scenario: Installation of enterprise software patches by SCCM (System Center Configuration Manager).
ccmsetup.exe) that utilizes the EXE32Pack structure to unpack and install MSI payloads.Process Name is ccmexec.exe or ccmsetup.exe AND User Account starts with SYSTEM or CCM.Scenario: Runtime execution of Java-based enterprise applications (e.g., SAP GUI, Oracle Forms).