This detection identifies the presence of executable files packed by Turbo Power Software’s v70 packer, which adversaries often leverage to obfuscate malicious payloads and evade signature-based scanning. Proactively hunting for this behavior in Azure Sentinel allows the SOC team to uncover hidden threats that may bypass initial defenses due to their compressed structure, ensuring early visibility into potential supply chain or fileless attacks.
rule EXEPackerv70byTurboPowerSoftware
{
meta:
author="malware-lu"
strings:
$a0 = { 1E 06 8C C3 83 [2] 2E [4] B9 [2] 8C C8 8E D8 8B F1 4E 8B FE }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 4 specific false positive scenarios for the EXEPackerv70byTurboPowerSoftware detection rule, along with suggested filters or exclusions:
Scenario: Deployment of TurboPower VCL (Visual Component Library) updates via SCCM/Intune.
TurboPowerSetup.exe) often triggers this rule as it is packed by the same engine.C:\Program Files\TurboPower\VCL\Installer\*.exe and exclude process names containing TurboPowerSetup.Scenario: Execution of legacy custom reporting tools by Finance Department.
ReportGen.exe) which matches the rule signature.C:\Apps\Finance\Reports\ReportGen.exe when the parent process is TaskHost.exe or svchost.exe.Scenario: Automated backup of TurboPower-based development environments.
VeeamTransport.exe or VeeamAgentService.exe, specifically targeting paths within `C