This rule detects the presence of the HidePE101BGCorp YARA signature, which typically identifies obfuscated or packed executables associated with specific malware families or custom backdoors. Proactively hunting for this indicator in Azure Sentinel allows the SOC to identify compromised endpoints or suspicious file artifacts before they progress to lateral movement or data exfiltration, reducing the mean time to detect (MTTD) for stealthy threats.
rule HidePE101BGCorp
{
meta:
author="malware-lu"
strings:
$a0 = { BA [3] 00 B8 [4] 89 02 83 C2 04 B8 [4] 89 02 83 C2 04 B8 [4] 89 02 83 C2 F8 FF E2 0D 0A 2D 3D 5B 20 48 69 64 65 50 45 20 62 79 20 42 47 43 6F 72 70 20 5D 3D 2D }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
bin or obj directories. The YARA rule may match specific header patterns or section names common in debug builds or specific compiler outputs.
devenv.exe, code.exe, idea64.exe) and the file path contains standard build directories like \bin\ or \obj\..exe or .dll files. During extraction, the archive utility writes PE files to disk, and if the YARA rule scans files during I/O operations or if the extraction process itself is flagged due to its handling of PE structures, it may trigger a false positive.
7z.exe, winrar.exe, or rar.exe and the operation type is “Create” or “Write” for files with extensions .exe, .dll, or .sys.MsMpEng.exe (Defender) or FalconSensor.exe (CrowdStrike) and the file path is under `C