This rule detects the presence of the Reg2Exe utility, a tool frequently used by adversaries to convert Windows registry keys into executable files, often to facilitate persistence or privilege escalation. Proactively hunting for this artifact in Azure Sentinel allows the SOC team to identify potential staging or execution activities that may have bypassed standard file-based detections, ensuring early visibility into low-severity but tactically significant adversary actions.
rule Reg2Exe222223byJanVorel
{
meta:
author="malware-lu"
strings:
$a0 = { 6A 00 E8 2F 1E 00 00 A3 C4 35 40 00 E8 2B 1E 00 00 6A 0A 50 6A 00 FF 35 C4 35 40 00 E8 07 00 00 00 50 E8 1B 1E 00 00 CC 68 48 00 00 00 68 00 00 00 00 68 C8 35 40 00 E8 76 16 00 00 83 C4 0C 8B 44 24 04 A3 CC 35 40 00 68 00 00 00 00 68 A0 0F 00 00 68 00 00 00 00 E8 EC 1D 00 00 A3 C8 35 40 00 E8 62 1D 00 00 E8 92 1A 00 00 E8 80 16 00 00 E8 13 14 00 00 68 01 00 00 00 68 08 36 40 00 68 00 00 00 00 8B 15 08 36 40 00 E8 71 3F 00 00 B8 00 00 10 00 BB 01 00 00 00 E8 82 3F 00 00 FF 35 48 31 40 00 B8 00 01 00 00 E8 0D 13 00 00 8D 0D EC 35 40 00 5A E8 F2 13 00 00 68 00 01 00 00 FF 35 EC 35 40 00 E8 84 1D 00 00 A3 F4 35 40 00 FF 35 48 31 40 00 FF 35 F4 35 40 00 FF 35 EC 35 40 00 E8 }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Scenario: A developer or IT administrator uses a legitimate build tool or installer (e.g., NSIS, Inno Setup, or WiX Toolset) to compile a script or configuration file into an executable binary. This process often involves writing registry keys to track installation state or versioning, which may coincide with the execution of the generated .exe file, triggering the rule if it monitors for registry-to-executable transitions.
makensis.exe, iscc.exe, candle.exe) or where the working directory is a designated build folder (e.g., C:\Builds\, C:\Projects\).Scenario: A standard Windows scheduled task or service (e.g., Windows Update, Defender Update, or Office Click-to-Run) performs a routine update or maintenance cycle. These services frequently write to the registry to log status, timestamps, or configuration changes, and then spawn or restart helper executables (e.g., svchost.exe launching wuauclt.exe or MsMpEng.exe launching update helpers).
svchost.exe with specific service names like wuauserv or WinDefend) or where the executable path resides in C:\Windows\System32\ or C:\Program Files\Microsoft\.Scenario: An enterprise application installer (e.g., Adobe Creative Cloud, VMware Workstation, or Citrix Receiver) runs a post-install configuration script that writes registry keys for licensing or feature flags and then launches the main application executable or a helper service. This is a common pattern in MSI-based or custom installers that use