This detection identifies potential malware activity utilizing the SimplePack111 packing method with bagieTMX characteristics, which often indicates obfuscated payloads designed to evade signature-based defenses. Proactive hunting for this pattern in Azure Sentinel is essential to uncover stealthy threats that may bypass standard alerts due to their low severity and specialized packaging techniques.
rule SimplePack111Method1bagieTMX
{
meta:
author="malware-lu"
strings:
$a0 = { 60 E8 00 00 00 00 5B 8D 5B FA BD 00 00 [2] 8B 7D 3C 8D 74 3D 00 8D BE F8 00 00 00 0F B7 76 06 4E 8B 47 10 09 C0 74 55 0F B7 47 22 09 C0 74 4D 6A 04 68 00 10 00 00 FF 77 10 6A 00 FF 93 38 03 00 00 50 56 57 89 EE 03 77 0C 8B 4F 10 89 C7 89 C8 C1 E9 02 FC }
$a1 = { 60 E8 00 00 00 00 5B 8D 5B FA BD 00 00 [2] 8B 7D 3C 8D 74 3D 00 8D BE F8 00 00 00 0F B7 76 06 4E 8B 47 10 09 C0 74 55 0F B7 47 22 09 C0 74 4D 6A 04 68 00 10 00 00 FF 77 10 6A 00 FF 93 38 03 00 00 50 56 57 89 EE 03 77 0C 8B 4F 10 89 C7 89 C8 C1 E9 02 FC F3 A5 89 C1 83 E1 03 F3 A4 5F 5E 8B 04 24 89 EA 03 57 0C E8 3F 01 00 00 58 68 00 40 00 00 FF 77 10 50 FF 93 3C 03 00 00 83 C7 28 4E 75 9E BE [4] 09 F6 0F 84 0C 01 00 00 01 EE 8B 4E 0C 09 C9 0F 84 FF 00 00 00 01 E9 89 CF 57 FF 93 30 03 00 00 09 C0 75 3D 6A 04 68 00 10 00 00 68 00 10 00 00 6A 00 FF 93 38 03 00 00 89 C6 8D 83 6F 02 00 00 57 50 56 FF 93 44 03 00 00 6A 10 6A 00 56 6A 00 FF 93 48 03 00 00 89 E5 }
condition:
$a0 at pe.entry_point or $a1 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 2 string patterns in its detection logic.
Here are 5 specific false positive scenarios for the SimplePack111Method1bagieTMX detection rule, including suggested filters and exclusions:
Scenario: Microsoft Defender Antivirus Signature Updates
mpcmd.exe process (Microsoft Defender) frequently downloads and unpacks signature definition updates. These updates often contain compressed archives that match the structural patterns detected by the YARA rule, triggering alerts when the engine extracts new definitions during its scheduled daily update cycle.ImageName equals mpcmd.exe and the parent process is SenseService.exe or MsMpEng.exe. Alternatively, add a filter to ignore events occurring within 15 minutes of the standard “Antivirus Update” scheduled task (Microsoft-Windows-Defender).Scenario: SCCM (Configuration Manager) Software Deployment
ccmexec.exe agent, it often utilizes a custom packaging method that compresses payloads before installation. The extraction of these .msi or .appx packages by the SCCM client service mimics the behavior profile defined in the YARA rule.ImageName contains ccmexec.exe and the command line arguments include /install or /deploy. Additionally, whitelist the specific file paths associated with the SCCM cache directory (e.g., C:\Windows\CCM\Cache).Scenario: Scheduled Backup Jobs via Veeam Agent