This detection identifies potential adversary activity involving encrypted Portable Executable (PE) files that may indicate stealthy malware or data exfiltration attempts within the environment. A proactive hunt is essential in Azure Sentinel to uncover these subtle indicators early, as low-severity alerts often represent initial access stages of sophisticated attacks that could escalate if left uninvestigated.
rule PE_Admin10EncryptPE12003518SoldFlyingCat
{
meta:
author="malware-lu"
strings:
$a0 = { 60 9C 64 FF 35 00 00 00 00 E8 79 01 00 00 90 00 00 00 00 00 00 00 00 00 00 00 [8] 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [36] 00 00 00 00 6B 65 72 6E 65 6C 33 32 2E 64 6C 6C 00 00 00 47 65 74 53 79 73 74 65 6D 44 69 72 65 63 74 6F 72 79 41 00 00 00 43 72 65 61 74 65 46 69 6C 65 41 00 00 00 43 72 65 61 74 65 46 69 6C 65 4D 61 70 70 69 6E 67 41 00 00 00 4D 61 70 56 69 65 77 4F 66 46 69 6C 65 00 00 00 55 6E 6D 61 70 56 69 65 77 4F 66 46 69 6C 65 00 00 00 43 6C 6F 73 65 48 61 6E 64 6C 65 00 00 00 4C 6F 61 64 4C 69 62 72 61 72 79 41 00 00 00 47 65 74 50 72 6F 63 41 64 64 72 65 73 73 00 00 00 45 78 69 74 50 72 6F 63 65 73 73 }
$a1 = { 60 9C 64 FF 35 00 00 00 00 E8 79 01 00 00 90 00 00 00 00 00 00 00 00 00 00 00 [8] 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [36] 00 00 00 00 6B 65 72 6E 65 6C 33 32 2E 64 6C 6C 00 00 00 47 65 74 53 79 73 74 65 6D 44 69 72 65 63 74 6F 72 79 41 00 00 00 43 72 65 61 74 65 46 69 6C 65 41 00 00 00 43 72 65 61 74 65 46 69 6C 65 4D 61 70 70 69 6E 67 41 00 00 00 4D 61 70 56 69 65 77 4F 66 46 69 6C 65 00 00 00 55 6E 6D 61 70 56 69 65 77 4F 66 46 69 6C 65 00 00 00 43 6C 6F 73 65 48 61 6E 64 6C 65 00 00 00 4C 6F 61 64 4C 69 62 72 61 72 79 41 00 00 00 47 65 74 50 72 6F 63 41 64 64 72 65 73 73 00 00 00 45 78 69 74 50 72 6F 63 65 73 73 00 00 00 00 }
condition:
$a0 at pe.entry_point or $a1 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 2 string patterns in its detection logic.
Here are 4 specific false positive scenarios for the detection rule PE_Admin10EncryptPE12003518SoldFlyingCat, including suggested filters and exclusions tailored for a legitimate enterprise environment:
Scenario: Microsoft Defender Antivirus Scheduled Scans
MsMpEng.exe process (Microsoft Defender) performs scheduled full or quick scans that generate temporary encrypted artifacts or utilize internal encryption modules matching the “SoldFlyingCat” signature pattern during peak hours.ParentProcessName is MsMpEng.exe AND ParentPath contains \Program Files\Windows Defender\. Alternatively, tune the rule to ignore events occurring during the standard maintenance window (e.g., 02:00–04:00 UTC).Scenario: Office 365 Click-to-Run Updates and Background Tasks
OfficeClickToRun.exe or Microsoft Office C2R VSTO processes frequently download and install encrypted updates. These background tasks often spawn child processes that handle certificate validation and payload encryption, which can mimic the specific PE structure detected by the “Admin10Encrypt” logic in the rule title.OfficeClickToRun.exe process path (C:\Program Files\Common Files\Microsoft Shared\ClickToRun). Additionally, exclude alerts where the file hash matches known Microsoft Office update signatures stored in your threat intelligence feed.Scenario: Enterprise Backup Solutions (e.g., Veeam or Commvault)