This rule identifies executable files compressed with the PECompact v1.46 packer, a technique often used by adversaries to reduce binary size and evade static analysis during initial access or payload delivery. Proactively hunting for these packed binaries in Azure Sentinel allows the SOC to detect potentially obfuscated malware or trojans that may be executing on endpoints or stored in cloud storage before they trigger more advanced behavioral detections.
rule PECompactv146
{
meta:
author="malware-lu"
strings:
$a0 = { EB 06 68 [4] C3 9C 60 E8 02 [3] 33 C0 8B C4 83 C0 04 93 8B E3 8B 5B FC 81 EB 0F A0 40 ?? 87 DD 8B 85 A6 A0 40 ?? 01 85 03 A0 40 ?? 66 C7 85 ?? A0 40 ?? 90 90 01 85 9E A0 40 ?? BB 60 12 }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Legacy Application Deployment via Group Policy Objects (GPO)
C:\Program Files\, C:\Program Files (x86)\) that match specific known hashes or file names associated with the deployed legacy software. Alternatively, whitelist the specific SHA256 hash of the PECompact-compressed binary.Third-Party Antivirus/EDR Self-Update or Component Installation
C:\ProgramData\ or C:\Windows\System32\.svc_crowdstrike, svc_edr) or located in vendor-specific subdirectories (e.g., C:\ProgramData\CrowdStrike\). Whitelist the specific path pattern for the vendor’s update/installer components.Scheduled Task Execution of Compressed Utility Scripts