This hunt detects the execution of 32-bit executables packed with the UPX v1.38 format, a technique frequently employed by adversaries to obfuscate malicious binaries and evade static analysis. Proactively hunting for this behavior in Azure Sentinel allows the SOC team to identify potential stealthy malware or legitimate tools that may be hiding suspicious payloads within compressed archives before they trigger higher-severity alerts.
rule EXE32Packv138
{
meta:
author="malware-lu"
strings:
$a0 = { 3B C0 74 02 81 83 55 3B C0 74 02 81 83 53 3B C9 74 01 BC [4] 02 81 [7] 3B DB 74 01 BE 5D 8B D5 81 ED DC 8D 40 }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 5 specific false positive scenarios for the EXE32Packv138 detection rule, including suggested filters and exclusions:
Scenario: Execution of the Microsoft Office Click-to-Run Updater (OfficeC2RClient.exe) during a scheduled maintenance window.
ProcessName is OfficeC2RClient.exe AND CommandLine contains /update or /install, specifically running under the SYSTEM or a known service account (e.g., DOMAIN\svc-updates).Scenario: Deployment of a new application via Microsoft Endpoint Configuration Manager (SCCM/MECM) using the Application Deployment Service.
C:\Windows\CCM\Cache\* or processes spawned by ccmexec.exe where the parent process is ccmsetup.exe.Scenario: Routine antivirus definition update execution by CrowdStrike Falcon or Symantec Endpoint Protection.
ParentProcessName is FalconSensor.exe, Symantec.exe, or rtvscan64.exe, and the file extension is .exe located within the vendor’s installation directory (e.g., C:\Program Files\CrowdStrike\).**Scenario