This detection identifies the presence of the ConquestOfTroy.com packer, a tool frequently used by threat actors to obfuscate malicious payloads and evade static analysis. Proactively hunting for this signature in Azure Sentinel allows the SOC to uncover hidden malware artifacts on endpoints before they can execute or propagate, reducing the risk of undetected compromise.
rule PrivatePersonalPackerPPP103ConquestOfTroycom
{
meta:
author="malware-lu"
strings:
$a0 = { E8 19 00 00 00 90 90 E8 68 00 00 00 FF 35 2C 37 00 10 E8 ED 01 00 00 6A 00 E8 2E 04 00 00 E8 41 04 00 00 A3 74 37 00 10 6A 64 E8 5F 04 00 00 E8 30 04 00 00 A3 78 37 00 10 6A 64 E8 4E 04 00 00 E8 1F 04 00 00 A3 7C 37 00 10 A1 74 37 00 10 8B 1D 78 37 00 10 2B D8 8B 0D 7C 37 00 10 2B C8 83 FB 64 73 0F 81 F9 C8 00 00 00 73 07 6A 00 E8 D9 03 00 00 C3 6A 0A 6A 07 6A 00 E8 D3 03 00 00 A3 20 37 00 10 50 6A 00 E8 DE 03 00 00 A3 24 37 00 10 FF 35 20 37 00 10 6A 00 E8 EA 03 00 00 A3 30 37 00 10 FF 35 24 37 00 10 E8 C2 03 00 00 A3 28 37 00 10 8B 0D 30 37 00 10 8B 3D 28 37 00 10 EB 09 49 C0 04 39 55 80 34 39 24 0B C9 }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
InventoryManager.exe) that was originally compiled using the Conquest of Troy packer to reduce file size. The binary is being copied from a network share to a user’s desktop for testing.
C:\Apps\InventoryManager\) or allowlist the specific hash of the known legacy binary.DiskCleanupTool.exe) to all workstations. The utility was packed with Conquest of Troy to obfuscate internal logic and reduce deployment size.
GPO or Svchost.exe under the SoftwareDistribution folder, or allowlist the specific path where GPO-deployed apps reside (e.g., C:\ProgramData\GPOApps\).C:\Users\<dev>\Projects\BuildOutput\) or allowlist the specific parent process (e.g., MSBuild.exe or dotnet.exe) when the file is being written.