This detection identifies potential ransomware activity by flagging processes that compress an unusually high number of resources, a behavior characteristic of encryption stages where adversaries rapidly archive files before locking them. Proactive hunting for this pattern in Azure Sentinel is essential to catch early-stage ransomware attacks before they escalate into widespread data unavailability and business disruption.
rule EXECryptor2xxmaxcompressedresources
{
meta:
author="malware-lu"
strings:
$a0 = { 55 8B EC 83 C4 EC FC 53 57 56 89 45 FC 89 55 F8 89 C6 89 D7 66 81 3E 4A 43 0F 85 23 01 00 00 83 C6 0A C7 45 F4 08 00 00 00 31 DB BA 00 00 00 80 43 31 C0 E8 11 01 00 00 73 0E 8B 4D F0 E8 1F 01 00 00 02 45 EF AA EB E9 E8 FC 00 00 00 0F 82 97 00 00 00 E8 F1 00 00 00 73 5B B9 04 00 00 00 E8 FD 00 00 00 48 74 DE 0F 89 C7 00 00 00 E8 D7 00 00 00 73 1B 55 BD 00 01 00 00 E8 D7 00 00 00 88 07 47 4D 75 F5 E8 BF 00 00 00 72 E9 5D EB A2 B9 01 00 00 00 E8 C8 00 00 00 83 C0 07 89 45 F0 C6 45 EF 00 83 F8 08 74 89 E8 A9 00 00 00 88 45 EF E9 7C FF FF FF B9 07 00 00 00 E8 A2 00 00 00 50 }
condition:
$a0
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 5 specific false positive scenarios for the EXECryptor2xxmaxcompressedresources detection rule, including suggested filters and exclusions:
Scenario: Automated Backup Compression by Veeam or Commvault
.7z, .zip, or proprietary archives during scheduled nightly windows. The YARA rule may flag the high volume of compressed resources generated by these services as anomalous encryption behavior.ImageFileName matches Veeam.Backup.Service.exe or commvault_agent.exe AND the parent process is a known service host (svchost.exe). Additionally, filter out events occurring during defined maintenance windows (e.g., 02:00–06:00 local time).Scenario: Microsoft Office Document Archiving via PowerShell Scripts
System.IO.Compression module. These scripts create multiple compressed files in rapid succession, triggering the “max compressed resources” threshold.CommandLine contains keywords like -Command, Compress-Archive, or System.IO.Compression.ZipFile. Specifically target paths under C:\Scripts\Archival\ or C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe.Scenario: Antivirus Real-Time Scanning of Large Compressed Attachments
.rar, .7z) containing nested archives, the endpoint protection suite (e.g., CrowdStrike Falcon, Microsoft Defender) extracts and scans these resources. The