This hypothesis targets the presence of PEPACK v10, a PE file packer frequently used by threat actors to compress executables and obscure code from static analysis tools. Proactively hunting for this specific packer signature in Azure Sentinel helps identify potentially malicious or obfuscated binaries that may have been deployed to endpoints, enabling early detection of stealthy malware before it executes or spreads.
rule PEPACKv10byANAKiN1998
{
meta:
author="malware-lu"
strings:
$a0 = { 74 ?? E9 [4] 00 00 00 00 }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Legacy Application Deployment via Group Policy:
C:\Windows\Installer or application install directories.C:\Program Files\, C:\Program Files (x86)\) or specific known vendor directories (e.g., C:\Program Files\LegacyApp\). Additionally, exclude files with a valid digital signature from a trusted vendor certificate.Scheduled Backup or Archiving Jobs:
C:\Temp or C:\Users\Public\Documents, it may flag these benign, short-lived artifacts.C:\Temp, C:\Users\*\AppData\Local\Temp) that are less than 5MB in size and have a creation time within the last 1 hour. Alternatively, exclude files owned by service accounts associated with backup software (e.g., VeeamBackup, CommvaultService).Development and Testing Environments: