This detection identifies the execution of a specific packed application library (RLPack v118) that may indicate an adversary utilizing custom or obfuscated code to establish persistence within the environment. SOC teams should proactively hunt for this signature in Azure Sentinel to validate legitimate business usage and distinguish it from potential stealthy malware leveraging similar packing mechanisms to evade standard detection.
rule RLPackv118BasicaPLibAp0x
{
meta:
author="malware-lu"
strings:
$a0 = { 60 E8 00 00 00 00 8B 2C 24 83 C4 04 8D B5 1A 04 00 00 8D 9D C1 02 00 00 33 FF E8 61 01 00 00 EB 0F FF 74 37 04 FF 34 37 FF D3 83 C4 08 83 C7 08 83 3C 37 00 75 EB 83 BD 06 04 00 00 00 74 0E 83 }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 5 specific false positive scenarios for the RLPackv118BasicaPLibAp0x detection rule, along with targeted filtering strategies:
Scenario: Automated Application Deployment via Microsoft Endpoint Configuration Manager (SCCM)
RLPack signature structure within the temporary staging folder (C:\Windows\CCM\Logs).SMS_EXECUTIVE service account or filter by process path: C:\Program Files (x86)\Microsoft Configuration Manager\AdminConsole. Add a condition to ignore events occurring between 01:00 and 05:00 local time.Scenario: Antivirus Heuristic Scanning of Compressed Archives
.zip or .7z archives downloaded by users. The scanner’s internal decompression engine utilizes the same RLPack library to inspect nested files, triggering a hit before the file is fully written.MsMpEng.exe (Defender) or FalconSensorService.exe when they interact with files in user download directories (C:\Users\*\Downloads). Exclude events where the parent process is a known browser (Chrome, Edge).Scenario: Scheduled Backup Job Executing via Veeam Agent
RLPack before writing them to the repository storage, causing the YARA rule to