This detection identifies the execution of the PECrypt32 console application across versions 10, 10.1, and 10.2, which adversaries may leverage to obfuscate malicious payloads or establish a foothold within the environment. Proactively hunting for this behavior in Azure Sentinel is essential to distinguish legitimate administrative usage from anomalous instances that could indicate early-stage encryption-based attacks or unauthorized tool deployment.
rule PECrypt32Consolev10v101v102
{
meta:
author="malware-lu"
strings:
$a0 = { E8 00 00 00 00 5B 83 EB 05 EB 04 52 4E 44 21 EB 02 CD 20 EB }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 4 specific false positive scenarios for the PECrypt32Console detection rule, including suggested filters and exclusions:
Scenario: Microsoft Office Click-to-Run Self-Update Execution
OfficeC2RClient.exe process frequently invokes PECrypt32Console.exe (or a similarly named component within the Office installation directory) to decrypt configuration files or manage licensing tokens during background updates. This often occurs on user workstations between 09:00 and 17:00.OfficeC2RClient.exe running from the standard Office installation path (C:\Program Files\Microsoft Office\root\Office*\). Alternatively, filter based on the command line argument containing --update-task.Scenario: Scheduled Antivirus Policy Refresh via Group Policy
PECrypt32Console.exe to decrypt and apply new policy definitions stored in the %ProgramData% directory.C:\ProgramData\Microsoft\Windows Defender\Platform\*\PECrypt32Console.exe. Additionally, exclude events triggered by the specific Scheduled Task name “WD-Scan-PolicyRefresh” or similar vendor-specific task identifiers.Scenario: Legacy Line-of-Business (LOB) Application Deployment
PECrypt32Console as a helper utility to decrypt user session data upon login. This is common