This hunt detects the presence of PECompact v1.10b5 packed executables that may indicate an adversary utilizing compression to obscure malicious code and evade static analysis. A SOC team should proactively hunt for this signature in Azure Sentinel to identify potentially benign yet suspicious artifacts that could serve as a precursor to more complex attack chains or lateral movement activities.
rule PECompactv110b5
{
meta:
author="malware-lu"
strings:
$a0 = { EB 06 68 [4] C3 9C 60 E8 02 [3] 33 C0 8B C4 83 C0 04 93 8B E3 8B 5B FC 81 EB 0F 60 40 ?? 87 DD 8B 85 95 60 40 ?? 01 85 03 60 40 ?? 66 C7 85 ?? 60 40 ?? 90 90 BB 49 }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 4 specific false positive scenarios for the PECompactv110b5 detection rule, tailored for an enterprise environment:
Scenario: Microsoft Defender Antivirus Self-Update Execution
wuauserv) or the Microsoft Defender service (SenseService) frequently executes compacted PE binaries during scheduled update cycles to download and install new definition packages. These binaries often match the PECompactv110b5 signature due to their optimized packaging structure.\Program Files\Windows Defender\MpCmdRun.exe or \System32\wuauclt.exe where the parent process is svchost.exe. Additionally, filter out events occurring during the defined maintenance window (e.g., 01:00 – 05:00 local time).Scenario: Sysinternals Process Explorer or ProcDump Usage
ProcDump.exe or ProcessExplorer.exe to capture memory dumps or analyze running processes. These tools are distributed as compacted PE executables that trigger the rule when launched manually or via scheduled tasks for health checks.Sysinternals Suite v2024). Alternatively, exclude any process where the command line contains arguments like -ma, -accepteula, or -dumpifhung.Scenario: Automated Backup Client Operations (Veeam/Commvault)