This rule detects the presence of the EXEShieldV06SMoKE YARA signature, which typically indicates the use of a specific executable shielding or packing technique often employed by adversaries to obscure binary characteristics and evade static analysis. Proactively hunting for this pattern in Azure Sentinel allows the SOC team to identify potentially obfuscated malware or trojans that may have slipped past initial detection controls, ensuring early visibility into low-severity threats that could serve as precursors to more complex attacks.
rule EXEShieldV06SMoKE
{
meta:
author="malware-lu"
strings:
$a0 = { E8 04 00 00 00 83 60 EB 0C 5D EB 05 45 55 EB 04 B8 EB F9 00 C3 E8 00 00 00 00 5D 81 ED D4 1A 40 00 EB 01 00 8D B5 5E 1B 40 00 BA A1 0B 00 00 EB 01 00 8D 8D FF 26 40 00 8B 09 E8 14 00 00 00 83 EB 01 00 8B FE E8 00 00 00 00 58 83 C0 07 50 C3 00 EB 04 58 40 }
$a1 = { E8 04 00 00 00 83 60 EB 0C 5D EB 05 45 55 EB 04 B8 EB F9 00 C3 E8 00 00 00 00 5D 81 ED D4 1A 40 00 EB 01 00 8D B5 5E 1B 40 00 BA A1 0B 00 00 EB 01 00 8D 8D FF 26 40 00 8B 09 E8 14 00 00 00 83 EB 01 00 8B FE E8 00 00 00 00 58 83 C0 07 50 C3 00 EB 04 58 40 50 C3 8A 06 46 EB 01 00 D0 C8 E8 14 00 00 00 83 EB 01 00 2A C2 E8 00 00 00 00 5B 83 C3 07 53 C3 00 EB 04 5B 43 53 C3 EB 01 00 32 C2 E8 0B 00 00 00 00 32 C1 EB 01 00 C0 C0 02 EB 09 2A C2 5B EB 01 00 43 53 C3 88 07 EB 01 00 47 4A 75 B4 90 }
condition:
$a0 at pe.entry_point or $a1 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 2 string patterns in its detection logic.
EXEShield protection mechanism to prevent tampering or reverse engineering of the executable.
msiexec.exe, setup.exe, or install.exe and the file path contains \Program Files\ or \Program Files (x86)\.EXEShield for code integrity and anti-debugging features during normal user interaction.
\Adobe\, \JetBrains\, or specific finance application folders, and exclude if the process is spawned by a standard user interface process like explorer.exe or winword.exe.svchost.exe (specifically for the Task Scheduler service) or services.exe, and the command line contains arguments like /install, /update, or /reboot.C:\Dev\ or D:\Builds\.
Dev or QA security group, or if the file path matches common development directories such as \Dev\, \Builds\, or \Temp\ (with caution).