Hunt Hypothesis
This rule identifies executable files compressed with the PECompact v1.10b3 packer, a technique often used by adversaries to reduce binary size and evade static analysis during initial access or payload delivery. Proactively hunting for these signatures in Azure Sentinel allows the SOC team to detect potentially obfuscated malware artifacts before they execute, particularly in environments where compacted binaries may be staged or downloaded via web shells or phishing campaigns.
YARA Rule
rule PECompactv110b3
{
meta:
author="malware-lu"
strings:
$a0 = { EB 06 68 [4] C3 9C 60 E8 02 [3] 33 C0 8B C4 83 C0 04 93 8B E3 8B 5B FC 81 EB 0F 60 40 ?? 87 DD 8B 85 95 60 40 ?? 01 85 03 60 40 ?? 66 C7 85 ?? 60 40 ?? 90 90 BB 95 }
condition:
$a0 at pe.entry_point
}
Deployment Notes
This YARA rule can be deployed in the following contexts:
- Microsoft Defender for Endpoint — Custom indicators / advanced hunting
- Email Gateway — Attachment scanning
- File Share Monitoring — Periodic scanning of shared drives
- YARA CLI — Manual threat hunting on endpoints
This rule contains 1 string patterns in its detection logic.
False Positive Guidance
- Legacy Application Deployment via Group Policy: When deploying older line-of-business applications (e.g., legacy ERP clients or specialized engineering software) that were compiled using PECompact v1.10b3 to reduce file size, the binary will match the YARA signature.
- Filter/Exclusion: Exclude files located in specific application directories (e.g.,
C:\Program Files\LegacyERP\) or filter by known parent processes like gpupdate.exe or svchost.exe during GPO application.
- Third-Party Installer Execution: Many older or niche third-party installers (e.g., specific versions of Java JDK, old Adobe plugins, or specialized hardware drivers) use PECompact for compression. Running these installers from a network share or local drive will trigger the alert.
- Filter/Exclusion: Exclude execution paths under standard installer directories (e.g.,
C:\Temp\, C:\Users\<user>\Downloads\, or C:\ProgramData\Installers\) and correlate with known installer parent processes like msiexec.exe or setup.exe.
- Scheduled Maintenance Jobs for Legacy Tools: Scheduled tasks running legacy maintenance scripts or backup agents that rely on PECompact-compressed executables (common in older backup solutions or log rotation tools) will trigger the rule during their scheduled run times.
- Filter/Exclusion: Exclude processes spawned by
Task Scheduler (taskschd.mgr) or specific service hosts (svchost.exe) where the executable path matches known legacy tool directories (e.g., C:\Program Files\BackupAgent\bin\).
- Development and Testing Environments: Developers or QA engineers testing legacy application builds or running unit tests on compressed binaries in development folders will trigger the rule.
- Filter/Exclusion: Exclude paths containing keywords like
dev, `test