This detection identifies the presence of a specific packed library artifact (RLPackFullEdition) that may indicate an adversary utilizing custom or obfuscated components to establish persistence within the environment. Proactively hunting for this signature in Azure Sentinel is essential to uncover potential low-severity, stealthy deployments that could serve as a foothold for lateral movement before triggering higher-severity alerts.
rule RLPackFullEdition117aPLibAp0x
{
meta:
author="malware-lu"
strings:
$a0 = { 60 E8 00 00 00 00 8B 2C 24 83 C4 04 [15] 8D B5 74 1F 00 00 8D 9D 1E 03 00 00 33 FF [15] EB 0F FF 74 37 04 FF 34 }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 5 specific false positive scenarios for the RLPackFullEdition117aPLibAp0x detection rule, including suggested filters and exclusions:
Scenario: Automated Backup Execution by Veeam or Commvault
RLPack library during full edition scans to compress data streams. The rule may trigger when the backup service spawns a child process to handle large file archives, mimicking the behavior of a malicious packer.-backup or specific service names like VeeamService.exe and CommServe.exe. Alternatively, whitelist the parent process path: C:\Program Files\Veeam\Backup and Replication\...Scenario: Microsoft Office 365 Click-to-Run Updates
OfficeClickToRun.exe) often invokes the RLPack library when applying cumulative updates or repairing installation components. This activity involves unpacking and repacking of .appx bundles, which matches the YARA signature’s logic for legitimate application deployment.OfficeClickToRun.exe located in C:\Program Files\Microsoft Office Root\Office16\. Additionally, filter by file extension .appx or .msi if the rule inspects file types.Scenario: Scheduled Antivirus Deep Scan (CrowdStrike or SentinelOne)
RLPack component for on-the