This hypothesis targets the presence of the SecuPack v15 packer, a technique often used by adversaries to compress or obfuscate malicious payloads to evade static analysis and signature-based detection. Proactively hunting for this specific packer in Azure Sentinel allows the SOC team to identify potentially hidden or modified executables before they can be executed, reducing the risk of low-severity threats that may serve as initial access vectors or part of a larger attack chain.
rule SecuPackv15
{
meta:
author="malware-lu"
strings:
$a0 = { 55 8B EC 83 C4 F0 53 56 57 33 C0 89 45 F0 B8 CC 3A 40 ?? E8 E0 FC FF FF 33 C0 55 68 EA 3C 40 ?? 64 FF 30 64 89 20 6A ?? 68 80 [3] 6A 03 6A ?? 6A 01 [3] 80 }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
SecuPackv15 YARA rule.
C:\Program Files\CrowdStrike\ or C:\ProgramData\Microsoft Defender\) or filter by process names like FalconSensor.exe, MsMpEng.exe, or SentinelOneAgent.exe performing the write operation.wuaexhost.exe (Windows Update), ccmexec.exe (SCCM Client), or gpupdate.exe, or filter by file paths within the C:\Windows\Installer or C:\Program Files\ directories during known maintenance windows..vbk, .cab, or .zip) that contain packed or compressed data structures. If the YARA rule scans these temporary files or the backup agent’s own binary, it may flag the compressed data as a match.
VeeamBackup.exe, commvault.exe, or