This detection identifies 32-bit executable files packed with the v13x compression algorithm, a technique often employed by adversaries to obscure malicious code and evade signature-based scanning. Proactively hunting for these artifacts in Azure Sentinel is essential because low-severity detections of packed executables can serve as early indicators of stealthy initial access or lateral movement attempts that might otherwise be overlooked amidst routine system noise.
rule EXE32Packv13x
{
meta:
author="malware-lu"
strings:
$a0 = { 3B ?? 74 02 81 83 55 3B ?? 74 02 81 ?? 53 3B ?? 74 01 [5] 02 81 [2] E8 [4] 3B 74 01 ?? 5D 8B D5 81 ED }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 5 specific false positive scenarios for the EXE32Packv13x detection rule, along with suggested filters and exclusions:
Scenario: Scheduled Antivirus Definition Updates
EXE32Packv13x signature often matches the update agent’s payload structure.C:\Program Files\Microsoft Defender\MpCmdRun.exe or C:\ProgramData\CrowdStrike\FalconSensor\Tools\UpdateService.exe) and exclude file paths containing \Updates\ or \Definitions\.Scenario: Legacy Line-of-Business Application Installers
System account with a known digital signature from internal Certificate Authorities (CA) and restrict detection to file extensions .msi, .exe within the C:\Program Files\InternalApps\ directory tree.Scenario: Automated Patch Management Deployments