This rule identifies executable files compressed with the PECompact v1.56 packer, a technique often used by adversaries to reduce file size and obscure code structure to evade static analysis. Proactively hunting for this specific packer version in Azure Sentinel allows the SOC team to surface potentially obfuscated binaries that may be executing in the environment, ensuring that low-severity but suspicious artifacts are not overlooked during routine monitoring.
rule PECompactv156
{
meta:
author="malware-lu"
strings:
$a0 = { EB 06 68 [4] C3 9C 60 E8 02 [3] 33 C0 8B C4 83 C0 04 93 8B E3 8B 5B FC 81 EB 0F 90 40 ?? 87 DD 8B 85 A2 90 40 ?? 01 85 03 90 40 ?? 66 C7 85 ?? 90 40 ?? 90 90 01 85 9E 90 40 ?? BB 2D 12 }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Antivirus/EDR Engine Updates: When enterprise endpoint protection platforms (e.g., CrowdStrike Falcon, Microsoft Defender for Endpoint, or SentinelOne) update their detection engines or heuristics, they may temporarily store or execute compressed PE files that match the PECompact signature.
CsfalconService.exe, MsMpEng.exe, SentinelOneAgent.exe) or filter by file path containing Program Files\ and CrowdStrike\, Microsoft\Windows Defender\, or SentinelOne\.Legacy Application Deployment via SCCM/Intune: System Center Configuration Manager (SCCM) or Microsoft Intune often deploys legacy line-of-business applications that were compiled with older compression tools (like PECompact or UPX) to reduce download size. These files are typically executed during scheduled maintenance windows.
ccmexec.exe (SCCM) or IntuneAgent.exe, or filter by known application installation directories (e.g., C:\Program Files\LegacyApp\) and specific scheduled task names (e.g., SCCM_AppDeploy_LegacyApp).Third-Party Installer Bootstrappers: Many enterprise software installers (e.g., Adobe Creative Cloud, Oracle Java, or .NET Framework) use compressed PE stubs to unpack and execute the main installer. These stubs often reside in temporary directories or specific installer folders and are executed by msiexec.exe or setup.exe.
C:\Windows\Installer\, C:\ProgramData\Package Cache\, or C:\Users\<User>\AppData\Local\Temp\ where the