This rule identifies the presence of binaries protected by the Themida 10.x.x.1800 compression engine, a technique frequently employed by adversaries to obscure code execution and evade static analysis. Proactively hunting for these signatures in Azure Sentinel allows the SOC to detect potentially obfuscated malware or custom tools that may be leveraging commercial packers to hide their true intent within the environment.
rule Themida10xx1800compressedengineOreansTechnologies
{
meta:
author="malware-lu"
strings:
$a0 = { B8 [4] 60 0B C0 74 58 E8 00 00 00 00 58 05 43 00 00 00 80 38 E9 75 03 61 EB 35 E8 00 00 00 00 58 25 00 F0 FF FF 33 FF 66 BB 19 5A 66 83 C3 34 66 39 18 75 12 0F B7 50 3C 03 D0 BB E9 44 00 00 83 C3 67 39 1A 74 07 2D 00 10 00 00 EB DA 8B F8 B8 }
$a1 = { B8 [4] 60 0B C0 74 58 E8 00 00 00 00 58 05 43 00 00 00 80 38 E9 75 03 61 EB 35 E8 00 00 00 00 58 25 00 F0 FF FF 33 FF 66 BB 19 5A 66 83 C3 34 66 39 18 75 12 0F B7 50 3C 03 D0 BB E9 44 00 00 83 C3 67 39 1A 74 07 2D 00 10 00 00 EB DA 8B F8 B8 [4] 03 C7 B9 5A [3] 03 CF EB 0A B8 [4] B9 5A [3] 50 51 E8 84 00 00 00 E8 00 00 00 00 58 2D 26 00 00 00 B9 EF 01 00 00 C6 00 E9 83 E9 05 89 48 01 61 E9 AF 01 }
condition:
$a0 at pe.entry_point or $a1 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 2 string patterns in its detection logic.
Legitimate Commercial Software Updates (e.g., Adobe Creative Cloud, JetBrains IDEs)
AdobeUpdate.exe, JetBrainsUpdater.exe) or filter by specific image paths (e.g., C:\Program Files\Adobe\, C:\Program Files\JetBrains\).Game Launchers and Anti-Cheat Services (e.g., Steam, Epic Games, Riot Client)
steam.exe, EpicGamesLauncher.exe, RiotClient.exe) or filter by specific service names (e.g., RiotClientServices.exe, SteamWebHelper.exe).Virtual Machine and Container Image Extraction (e.g., VMware, Docker, Hyper-V)
vmware-vmx.exe, dockerd.exe, svchost.exe with specific service names