This YARA rule targets a specific instance of the RLPack packer utilizing LZMA compression, indicating the presence of a packed executable that may be used to obscure malicious code or reduce file size for stealthy delivery. Proactively hunting for this signature in Azure Sentinel allows the SOC team to identify potentially obfuscated binaries early in the environment, mitigating the risk of hidden payloads evading standard static analysis.
rule RLPack118LZMA430ap0x
{
meta:
author="malware-lu"
strings:
$a0 = { 60 E8 00 00 00 00 8B 2C 24 83 C4 ?? 8D B5 21 0B 00 00 8D 9D FF 02 00 00 33 FF E8 9F 01 00 00 6A ?? 68 [4] 68 [4] 6A 00 FF 95 AA 0A 00 00 89 85 F9 0A 00 00 EB 14 60 FF B5 F9 0A 00 00 FF 34 37 FF 74 37 04 FF D3 61 83 C7 ?? 83 3C 37 00 75 E6 83 BD 0D 0B 00 00 00 74 0E 83 BD 11 0B 00 00 00 74 05 E8 F6 01 00 00 8D 74 37 04 53 6A ?? 68 [4] 68 [4] 6A 00 FF 95 AA 0A 00 00 89 85 1D 0B 00 00 5B 60 FF B5 F9 0A 00 00 56 FF B5 1D 0B 00 00 FF D3 61 8B B5 1D 0B 00 00 8B C6 EB 01 }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
LZMA signature.
C:\Program Files\, C:\Program Files (x86)\) or specific known vendor paths (e.g., C:\Program Files\Adobe\, C:\Program Files\JetBrains\).7z.exe, tar.exe, make) often handle LZMA-compressed archives as part of build processes, dependency management (npm, pip), or source code packaging.
devenv.exe, idea64.exe, npm.exe, pip.exe) or files within developer workspace directories (e.g., C:\Users\<User>\Projects\, C:\dev\)..7z, .tar.lzma) may generate temporary files or logs that trigger the rule.
.7z, .tar.lzma, .lzma in backup directories (e.g., C:\Backup\, D:\Archive\) or exclude processes known to be backup agents (e.g., veeam.exe, commvault.exe).