This YARA rule targets specific packed executables utilizing the LZMA compression algorithm, indicating the presence of obfuscated malware designed to evade signature-based detection. Proactively hunting for these artifacts in Azure Sentinel allows the SOC team to identify stealthy payloads that may be executing on endpoints or stored in cloud storage, reducing the risk of undetected compromise from low-severity threats.
rule RLPackV119LZMA430ap0x
{
meta:
author="malware-lu"
strings:
$a0 = { 60 E8 00 00 00 00 8B 2C 24 83 C4 04 83 7C 24 28 01 75 0C 8B 44 24 24 89 85 49 0B 00 00 EB 0C 8B 85 45 0B 00 00 89 85 49 0B 00 00 8D B5 6D 0B 00 00 8D 9D 2F 03 00 00 33 FF 6A 40 68 00 10 00 00 68 00 20 0C 00 6A 00 FF 95 DA 0A 00 00 89 85 41 0B 00 00 E8 76 01 00 00 EB 20 60 8B 85 49 0B 00 00 FF B5 41 0B 00 00 FF 34 37 01 04 24 FF 74 37 04 01 04 24 FF D3 61 83 C7 08 83 3C 37 00 75 DA 83 BD 55 0B 00 00 00 74 0E 83 BD 59 0B 00 00 00 74 05 E8 D7 01 00 00 8D 74 37 04 53 6A 40 68 00 10 00 00 68 [4] 6A 00 FF 95 DA 0A 00 00 89 85 69 0B 00 00 5B 60 FF B5 41 0B 00 00 56 FF B5 69 0B 00 00 FF D3 61 8B B5 69 0B 00 00 8B C6 EB 01 40 80 38 01 75 FA 40 8B 38 03 BD 49 0B 00 00 83 C0 04 89 85 65 0B 00 00 E9 98 00 00 00 56 FF 95 D2 0A 00 00 89 85 61 0B 00 00 85 C0 0F 84 C8 00 00 00 8B C6 EB 5F 8B 85 65 0B 00 00 8B 00 A9 00 00 00 80 74 14 35 00 00 00 80 50 8B 85 65 0B 00 00 C7 00 20 20 20 00 EB 06 FF B5 65 0B 00 00 FF B5 61 0B 00 00 FF 95 D6 0A 00 00 85 C0 0F 84 87 00 00 00 89 07 83 C7 04 8B 85 65 0B 00 00 EB 01 40 80 38 00 75 FA 40 89 85 65 0B 00 00 66 81 78 02 00 80 74 A1 80 38 00 75 9C EB 01 46 80 3E 00 75 FA 46 40 8B 38 03 BD 49 0B 00 00 83 C0 04 89 85 65 0B 00 00 80 3E 01 0F 85 5F FF FF FF 68 00 40 00 00 68 [4] FF B5 69 0B 00 00 FF 95 DE 0A 00 00 68 00 40 00 00 68 00 20 0C 00 FF B5 41 0B 00 00 FF 95 DE 0A 00 00 E8 3D 00 00 00 E8 24 01 00 00 61 E9 [4] 61 C3 }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Scenario: A developer or DevOps engineer runs a build script that utilizes 7z (7-Zip) or LZMA compression libraries to package application artifacts or create .7z archives for deployment. The YARA rule may match the specific LZMA magic bytes or header structure within the compressed file or the executable itself if it statically links the compression library.
.7z, .tar, .zip, or .gz located in designated build output directories (e.g., C:\Builds\, /var/tmp/builds/). Additionally, exclude processes like 7z.exe, tar.exe, or python.exe when they are writing to these specific directories.Scenario: An enterprise backup agent (e.g., Veeam, Commvault, or Acronis) performs incremental backups using LZMA compression to reduce storage footprint. The backup client executable or the temporary backup files on the staging disk may trigger the rule if the YARA signature matches the compression header or the client binary’s embedded library.
vssadmin.exe, commvaultclient.exe, acronisagent.exe) and their associated temporary directories (e.g., C:\ProgramData\Veeam\, C:\Commvault\). Also, exclude files in backup staging folders (e.g., C:\BackupStaging\) that are larger than a certain threshold (e.g., >10MB) to avoid matching small header-only files.Scenario: A legacy Java or .NET application uses the java.util.zip or System.IO.Compression libraries internally, which may rely on LZMA or similar algorithms for data transfer or local caching. The process memory or temporary cache files created by the application might contain LZ