This YARA rule targets the RLPack10betaap0x signature, which likely identifies a specific variant of a packing tool or obfuscated payload used to conceal malicious code from static analysis. Proactively hunting for this signature in Azure Sentinel allows the SOC team to detect early-stage fileless or packed malware executions that may evade standard behavioral detections, ensuring visibility into low-severity threats that could serve as precursors to more complex intrusions.
rule RLPack10betaap0x
{
meta:
author="malware-lu"
strings:
$a0 = { 60 E8 00 00 00 00 8D 64 24 04 8B 6C 24 FC 8D B5 4C 02 00 00 8D 9D 13 01 00 00 33 FF EB 0F FF 74 37 04 FF 34 37 FF D3 83 C4 08 83 C7 08 83 3C 37 00 75 EB 8D 74 37 04 53 6A 40 68 00 10 00 00 68 [4] 6A 00 FF 95 F9 01 00 00 89 85 48 02 00 00 5B FF B5 }
$a1 = { 60 E8 00 00 00 00 8D 64 24 04 8B 6C 24 FC 8D B5 4C 02 00 00 8D 9D 13 01 00 00 33 FF EB 0F FF 74 37 04 FF 34 37 FF D3 83 C4 08 83 C7 08 83 3C 37 00 75 EB 8D 74 37 04 53 6A 40 68 00 10 00 00 68 [4] 6A 00 FF 95 F9 01 00 00 89 85 48 02 00 00 5B FF B5 48 02 00 00 56 FF D3 83 C4 08 8B B5 48 02 00 00 8B C6 EB 01 40 80 38 01 75 FA 40 8B 38 83 C0 04 89 85 44 02 00 00 EB 7A 56 FF 95 F1 01 00 00 89 85 40 02 00 00 8B C6 EB 4F 8B 85 44 02 00 00 8B 00 A9 00 00 00 80 74 14 35 00 00 00 80 50 8B 85 44 02 00 00 C7 00 20 20 20 00 EB 06 FF B5 44 02 00 00 FF B5 40 02 00 00 FF 95 F5 01 00 00 89 07 83 C7 04 8B 85 44 02 00 00 EB 01 40 80 38 00 75 FA 40 89 85 44 02 00 00 80 38 00 75 AC EB 01 46 80 3E 00 75 FA 46 40 8B 38 83 C0 04 89 85 44 02 00 00 80 3E 01 75 81 68 00 40 00 00 68 [4] FF B5 48 02 00 00 FF 95 FD 01 00 00 61 68 [4] C3 60 8B 74 24 24 8B 7C }
condition:
$a0 at pe.entry_point or $a1 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 2 string patterns in its detection logic.
Scenario: A developer or DevOps engineer is testing a custom application packaging tool or a beta version of a commercial installer (e.g., Inno Setup, NSIS, or a proprietary internal wrapper) that uses the RLPack compression algorithm in its beta release. The resulting executable or installer file contains the specific byte pattern RLPack10betaap0x as part of its header or metadata, triggering the YARA rule during a file scan or EDR ingestion.
C:\Dev\Builds\, \\fileserver\staging\) or exclude files with extensions like .exe or .msi if they are signed by the internal development team’s code-signing certificate. Alternatively, create a new YARA rule exception that checks for the presence of a valid Authenticode signature from the internal CA.Scenario: An IT administrator is deploying a patched or beta version of a third-party enterprise application (e.g., a beta release of Adobe Creative Cloud, a specific version of a Java-based middleware, or a custom .NET application) that incorporates the RLPack library for resource compression. The binary artifact contains the literal string RLPack10betaap0x in its resource section or debug symbols, which is a legitimate part of the build process for that specific beta channel.
C:\Program Files\VendorName\Beta\ or C:\Windows\Temp\ with specific vendor-specific filenames). A more robust filter would be to exclude files where the ProductVersion or FileVersion property matches the known beta version number of the affected application.Scenario: A security engineer or QA team is running a regression