This rule identifies executable files packed with specific Linker versions (v360, v364, v365, or 50121), a technique often employed by adversaries to obfuscate malware binaries and evade static signature-based detection. Proactively hunting for these specific packing characteristics allows the SOC to uncover stealthy payloads that may be executing in the environment before they trigger more complex behavioral alerts.
rule EXEPACKLINKv360v364v365or50121
{
meta:
author="malware-lu"
strings:
$a0 = { 8C C0 05 [2] 0E 1F A3 [2] 03 [3] 8E C0 8B [3] 8B ?? 4F 8B F7 FD F3 A4 50 B8 [2] 50 CB }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
setup.exe or msiexec.exe) is packed with a commercial packer like UPX or Aspack to reduce size and protect IP.
ccmsetup.exe, ccmexec.exe, or msiexec.exe, and the file path contains \Windows\CCM\ or \Program Files\Microsoft Configuration Manager\.Adobe Inc., Oracle Corporation, Symantec) and where the file path resides in standard installation directories like \Program Files\ or \Program Files (x86)\.7zG.exe for 7-Zip, WinRAR.exe, or Ninite.exe) that is packed to optimize startup time or protect the binary, often triggered by user login or system boot.
a, x, t, i) and the file name matches known utility binaries (7z*.exe, WinRAR.exe, Ninite.exe).