This rule identifies the presence of a self-decrypting binary generator, a technique often used by adversaries to obfuscate malicious payloads and evade static analysis during the initial stages of an attack. Proactively hunting for this indicator in Azure Sentinel allows the SOC to detect early-stage deployment activities or staging environments before the decrypted payload executes and establishes a foothold in the environment.
rule SDC12SelfDecryptingBinaryGeneratorbyClaesMNyberg
{
meta:
author="malware-lu"
strings:
$a0 = { 55 89 E5 83 EC 08 C7 04 24 01 00 00 00 FF 15 A0 91 40 00 E8 DB FE FF FF 55 89 E5 53 83 EC 14 8B 45 08 8B 00 8B 00 3D 91 00 00 C0 77 3B 3D 8D 00 00 C0 72 4B BB 01 00 00 00 C7 44 24 04 00 00 00 00 C7 04 24 08 00 00 00 E8 CE 24 00 00 83 F8 01 0F 84 C4 00 00 00 85 C0 0F 85 A9 00 00 00 31 C0 83 C4 14 5B 5D C2 04 00 3D 94 00 00 C0 74 56 3D 96 00 00 C0 74 1E 3D 93 00 00 C0 75 E1 EB B5 3D 05 00 00 C0 8D B4 26 00 00 00 00 74 43 3D 1D 00 00 C0 75 CA C7 44 24 04 00 00 00 00 C7 04 24 04 00 00 00 E8 73 24 00 00 83 F8 01 0F 84 99 00 00 00 85 C0 74 A9 C7 04 24 04 00 00 00 FF D0 B8 FF FF FF FF EB 9B 31 DB 8D 74 26 00 E9 69 FF FF FF C7 44 24 04 00 00 00 00 C7 04 24 0B 00 00 00 E8 37 24 00 00 83 F8 01 74 7F 85 C0 0F 84 6D FF FF FF C7 04 24 0B 00 00 00 8D 76 00 FF D0 B8 FF FF FF FF E9 59 FF FF FF C7 04 24 08 00 00 00 FF D0 B8 FF FF FF FF E9 46 FF FF FF C7 44 24 04 01 00 00 00 C7 04 24 08 00 00 00 E8 ED 23 00 00 B8 FF FF FF FF 85 DB 0F 84 25 FF FF FF E8 DB 15 00 00 B8 FF FF FF FF E9 16 FF FF FF C7 44 24 04 01 00 00 00 C7 04 24 04 00 00 00 E8 BD 23 00 00 B8 FF FF FF FF E9 F8 FE FF FF C7 44 24 04 01 00 00 00 C7 04 24 0B 00 00 00 E8 9F 23 00 00 B8 FF FF FF FF E9 DA FE FF FF }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Scenario: A developer or build engineer uses PyInstaller to package a Python application into a standalone executable for distribution. PyInstaller creates a self-extracting archive (SFX) that unpacks the Python interpreter and libraries into a temporary directory at runtime, which often matches the structural patterns of SDC12 generators.
C:\Projects\*\dist\, C:\Builds\*\out\) or where the parent process is a known build tool like python.exe or msbuild.exe with specific command-line arguments containing --onefile or --windowed.Scenario: An IT administrator deploys a custom PowerShell-based deployment script wrapped into an executable using PS2EXE or PowerShell2Exe to push configuration changes to endpoints without requiring PowerShell execution policy adjustments. These wrappers create a self-extracting binary that decrypts the embedded script in memory, triggering the YARA rule.
*.exe that were recently created (less than 24 hours) in administrative staging folders (e.g., C:\Admin\Deploy\, C:\Temp\Deploy\) and where the parent process is explorer.exe or cmd.exe initiated by a known admin user account.Scenario: A software vendor provides a self-extracting installer for a proprietary management agent (e.g., a custom EDR or monitoring agent) that uses a commercial SFX generator like NSIS (Nullsoft Scriptable Install System) or Inno Setup. These installers are designed to extract files and run setup routines, often exhibiting decryption behavior that mimics SDC12.