This rule detects the presence of PECompact-packed executables, a technique adversaries use to compress binary files to reduce file size and potentially evade signature-based detection. Proactively hunting for these artifacts in Azure Sentinel helps identify suspicious or malicious payloads that may have been deployed to endpoints, ensuring that compressed binaries are not overlooked during initial triage.
rule PECompactv166
{
meta:
author="malware-lu"
strings:
$a0 = { EB 06 68 [4] C3 9C 60 E8 02 [3] 33 C0 8B C4 83 C0 04 93 8B E3 8B 5B FC 81 EB 3F 90 40 ?? 87 DD 8B 85 E6 90 40 ?? 01 85 33 90 40 ?? 66 C7 85 ?? 90 40 ?? 90 90 01 85 DA 90 40 ?? 01 85 DE 90 40 ?? 01 85 E2 90 40 ?? BB 5B 11 }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
C:\Program Files\LegacyApp\, C:\Program Files (x86)\OldTool\) or paths containing specific vendor names if the application is known to use PECompact.C:\ProgramData\Veeam\Backup\, C:\Temp\Acronis\) or files with specific extensions associated with backup agents (e.g., .vbk, .tmp in specific agent folders).C:\Windows\Installer or C:\Temp directories during the process.
C:\Windows\Installer\ and C:\Temp\ if the parent process is a known installer (e.g., msiexec.exe, setup.exe from a specific vendor) or if the file age is less than 24 hours