This detection identifies potential archive-based malware execution patterns associated with the StrongBit domain, which may indicate an adversary utilizing compressed payloads to evade initial signature-based defenses. Proactive hunting for this behavior in Azure Sentinel is essential to uncover early-stage lateral movement or data exfiltration attempts that low-severity alerts might otherwise overlook during routine monitoring.
rule EXECryptor2223compressedcodewwwstrongbitcom
{
meta:
author="malware-lu"
strings:
$a0 = { E8 00 00 00 00 58 [5] 8B 1C 24 81 EB [4] B8 [4] 50 6A 04 68 00 10 00 00 50 6A 00 B8 C4 [3] 8B 04 18 FF D0 59 BA [4] 01 DA 52 53 50 89 C7 89 D6 FC F3 A4 B9 [4] 01 D9 FF D1 58 8B 1C 24 68 00 80 00 00 6A 00 50 }
$a1 = { E8 00 00 00 00 58 [5] 8B 1C 24 81 EB [4] B8 [4] 50 6A 04 68 00 10 00 00 50 6A 00 B8 C4 [3] 8B 04 18 FF D0 59 BA [4] 01 DA 52 53 50 89 C7 89 D6 FC F3 A4 B9 [4] 01 D9 FF D1 58 8B 1C 24 68 00 80 00 00 6A 00 50 B8 C8 [3] 8B 04 18 FF D0 59 58 5B 83 EB 05 C6 03 B8 43 89 03 83 C3 04 C6 03 C3 09 C9 74 46 89 C3 E8 A0 00 00 00 FC AD 83 F8 FF 74 38 53 89 CB 01 C3 01 0B 83 C3 04 AC 3C FE 73 07 25 FF 00 00 00 EB ED 81 C3 FE 00 00 00 09 C0 7A 09 66 AD 25 FF FF 00 00 EB DA AD 4E 25 FF FF FF 00 3D FF FF FF 00 75 CC [5] C3 }
condition:
$a0 or $a1
}
This YARA rule can be deployed in the following contexts:
This rule contains 2 string patterns in its detection logic.
Here are 5 specific false positive scenarios for the EXECryptor2223compressedcodewwwstrongbitcom detection rule, including suggested filters and exclusions:
Scenario: Automated Backup Compression by Veeam
vbr.exe service compresses large database snapshots into .zip or proprietary archive formats before transmission. This compression activity triggers the YARA rule due to the “compressed code” signature matching the StrongBit pattern.C:\Program Files\Veeam\Backup and Replication\Backup\VBService.exe (and its child processes) with an exclusion on the specific YARA rule ID.Scenario: Microsoft Office 365 Click-to-Run Updates
OfficeC2RClient.exe) periodically downloads and installs feature updates or language packs. These updates are often delivered as compressed .cab or .msi packages that contain embedded encrypted code segments similar to the StrongBit signature, causing a trigger during the installation phase.OfficeClickToRun.exe and filter out events where the file extension is .cab or .msi originating from the Microsoft Update service account (NT SERVICE\O365C2R).Scenario: Antivirus Heuristic Scanning by CrowdStrike
FalconService.exe) scans and temporarily compresses the file in memory