This rule detects the presence of PECompact, a legacy executable compression tool often used by adversaries to reduce the size of malware payloads and evade signature-based detection. Proactively hunting for this artifact in Azure Sentinel allows the SOC team to identify potentially obfuscated binaries that may have been dropped on endpoints or stored in cloud storage, ensuring that compressed executables are not overlooked during initial triage.
rule PECompactv167
{
meta:
author="malware-lu"
strings:
$a0 = { EB 06 68 [4] C3 9C 60 E8 02 [3] 33 C0 8B C4 83 C0 04 93 8B E3 8B 5B FC 81 EB 3F 90 40 87 DD 8B 85 E6 90 40 01 85 33 90 40 66 C7 85 90 40 90 90 01 85 DA 90 40 01 85 DE 90 40 01 85 E2 90 40 BB 8B 11 }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
C:\Program Files\, C:\Program Files (x86)\) that are owned by known service accounts or have a valid digital signature from a trusted vendor (e.g., Microsoft, Oracle, SAP).SYSTEM or NT AUTHORITY\LocalService account.
Task Scheduler (taskschd.msi or svchost.exe with specific service names) and the file path resides in vendor-specific directories (e.g., C:\ProgramData\VendorName\, C:\Windows\System32\Tasks\ associated binaries)..cab or .msi files in the same directory) or where the parent process is a known vendor installer service (e