This rule identifies Windows PE files that have been obfuscated using the UPX packer, a technique commonly employed by adversaries to compress executables and evade static analysis or signature-based detection. Proactively hunting for these packed binaries in Azure Sentinel allows the SOC team to uncover hidden payloads or suspicious artifacts that may indicate early-stage reconnaissance or the deployment of low-fidelity malware.
rule hmimyssPEPack01hmimys
{
meta:
author="malware-lu"
strings:
$a0 = { E8 00 00 00 00 5D 83 ED 05 6A 00 FF 95 E1 0E 00 00 89 85 85 0E 00 00 8B 58 3C 03 D8 81 C3 F8 00 00 00 80 AD 89 0E 00 00 01 89 9D 63 0F 00 00 8B 4B 0C 03 8D 85 0E 00 00 8B 53 08 80 BD 89 0E 00 00 00 75 0C 03 8D 91 0E 00 00 2B 95 91 0E 00 00 89 8D 57 0F 00 00 89 95 5B 0F 00 00 8B 5B 10 89 9D 5F 0F 00 00 8B 9D 5F 0F 00 00 8B 85 57 0F 00 00 53 50 E8 B7 0B 00 00 89 85 73 0F 00 00 6A 04 68 00 10 00 00 50 6A 00 FF 95 E9 0E 00 00 89 85 6B 0F 00 00 6A 04 68 00 10 00 00 68 D8 7C 00 00 6A 00 FF 95 E9 0E 00 00 89 85 6F 0F 00 00 8D 85 67 0F 00 00 8B 9D 73 0F 00 00 8B 8D 6B 0F 00 00 8B 95 5B 0F 00 00 83 EA 0E 8B B5 57 0F 00 00 83 C6 0E 8B BD 6F 0F 00 00 50 53 51 52 56 68 D8 7C 00 00 57 E8 01 01 00 00 8B 9D 57 0F 00 00 8B 03 3C 01 75 }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
UPX (Ultimate Packer for eXecutables) by a DevOps engineer or build server to compress application binaries for faster deployment or reduced disk footprint.
msbuild.exe, dotnet.exe, npm.exe) or where the file path resides in standard development directories (e.g., C:\dev\, C:\builds\, C:\src\).PECompact or similar packers by a software vendor’s CI/CD pipeline or a QA team testing release candidates for size optimization.
C:\QA\, C:\Staging\) or exclude processes initiated by service accounts associated with CI/CD systems (e.g., svc-cicd, build-agent).ASPack or MPRESS by a security team or application developer performing manual obfuscation or testing of packed executables in a controlled lab environment.
dev-, qa-, or lab-.UPX or PECompact by a scheduled maintenance job that re-compresses legacy application binaries to free up disk space on application servers.
svchost.exe (indicating a Windows Service) or Task Scheduler related processes, and the target file path is within known application directories (e.g., `C:\Program