This detection identifies the presence of a specific packed executable signature associated with potential fileless or obfuscated malware activity within the environment. Proactive hunting for this indicator in Azure Sentinel is essential to uncover stealthy threats that may evade standard signature-based defenses by analyzing process creation and memory behaviors linked to this YARA rule.
rule RLPackV119aPlib043ap0x
{
meta:
author="malware-lu"
strings:
$a0 = { 60 E8 00 00 00 00 8B 2C 24 83 C4 04 83 7C 24 28 01 75 0C 8B 44 24 24 89 85 3C 04 00 00 EB 0C 8B 85 38 04 00 00 89 85 3C 04 00 00 8D B5 60 04 00 00 8D 9D EB 02 00 00 33 FF E8 52 01 00 00 EB 1B 8B 85 3C 04 00 00 FF 74 37 04 01 04 24 FF 34 37 01 04 24 FF D3 83 C4 08 83 C7 08 83 3C 37 00 75 DF 83 BD 48 04 00 00 00 74 0E 83 BD 4C 04 00 00 00 74 05 E8 B8 01 00 00 8D 74 37 04 53 6A 40 68 00 10 00 00 68 [4] 6A 00 FF 95 D1 03 00 00 89 85 5C 04 00 00 5B FF B5 5C 04 00 00 56 FF D3 83 C4 08 8B B5 5C 04 00 00 8B C6 EB 01 40 80 38 01 75 FA 40 8B 38 03 BD 3C 04 00 00 83 C0 04 89 85 58 04 00 00 E9 94 00 00 00 56 FF 95 C9 03 00 00 85 C0 0F 84 B4 00 00 00 89 85 54 04 00 00 8B C6 EB 5B 8B 85 58 04 00 00 8B 00 A9 00 00 00 80 74 14 35 00 00 00 80 50 8B 85 58 04 00 00 C7 00 20 20 20 00 EB 06 FF B5 58 04 00 00 FF B5 54 04 00 00 FF 95 CD 03 00 00 85 C0 74 71 89 07 83 C7 04 8B 85 58 04 00 00 EB 01 40 80 38 00 75 FA 40 89 85 58 04 00 00 66 81 78 02 00 80 74 A5 80 38 00 75 A0 EB 01 46 80 3E 00 75 FA 46 40 8B 38 03 BD 3C 04 00 00 83 C0 04 89 85 58 04 00 00 80 3E 01 0F 85 63 FF FF FF 68 00 40 00 00 68 [4] FF B5 5C 04 00 00 FF 95 D5 03 00 00 E8 3D 00 00 00 E8 24 01 00 00 61 E9 [4] 61 C3 }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 5 specific false positive scenarios for the detection rule RLPackV119aPlib043ap0x, along with targeted filters and exclusions suitable for a legitimate enterprise environment:
Scenario: Microsoft Defender Antivirus Real-Time Scan
mpclient.dll or MsMpEng.exe when Microsoft Defender performs real-time scanning on user documents in high-traffic directories (e.g., C:\Users\Public\Documents). This often triggers during peak business hours.Microsoft Defender Antivirus Service (MsMpEng.exe) and exclude the specific directory path C:\Program Files\Windows Defender from the rule’s scope to prevent scanning of its own components.Scenario: Office 365 Click-to-Run Update Deployment
OfficeClickToRun.exe process extracts update packages containing packed libraries that match the RLPack signature pattern. This is common when deploying new feature updates to the enterprise fleet via Intune or SCCM.OfficeC2RClient.exe and limit detection to non-business hours (e.g., 01:00–05:00) or exclude the path C:\Program Files\Microsoft Office Root.Scenario: Visual Studio Build Agent Compilation
msbuild.exe process running on CI/CD agents (such as Azure DevOps Agents or Jenkins nodes) compiles C++ projects that utilize standard library packs matching the rule’s signature. This generates high-volume alerts during nightly build cycles.