This rule detects the presence of Thinstall, a software installer that can be leveraged by adversaries to package malicious payloads or obfuscate executable files during initial access or lateral movement. Proactively hunting for this indicator in Azure Sentinel allows the SOC team to identify potentially compromised endpoints or staging areas where attackers may be using Thinstall to bypass traditional file-based detection mechanisms.
rule Thinstall25
{
meta:
author="malware-lu"
strings:
$a0 = { 55 8B EC B8 [4] BB [4] 50 E8 00 00 00 00 58 2D A7 1A 00 00 B9 6C 1A 00 00 BA 20 1B 00 00 BE 00 10 00 00 BF B0 53 00 00 BD EC 1A 00 00 03 E8 81 75 00 [4] 81 75 04 [4] 81 75 08 [4] 81 75 0C [4] 81 75 10 }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
app_thin.exe) from a network share or local drive to test application performance or packaging integrity.
cmd.exe, powershell.exe, wt.exe [Windows Terminal]) and the file path resides in a designated development or staging directory (e.g., C:\Dev\, D:\Staging\, \\fileserver\dev\).backup_thin.exe) via Task Scheduler or a service.
svchost.exe (specifically those hosting the Task Scheduler service) or taskeng.exe, where the target file name matches known backup or maintenance tool patterns (e.g., *backup*.exe, *clean*.exe, *rotate*.exe).setup_thin.exe for Adobe Creative Cloud, JetBrains IDEs, or Oracle Java) uses Thinstall compression to reduce installation size, and the installer is executed by the user or an automated deployment tool (e.g., SCCM, PDQ Deploy).
ccmexec.exe, pdqdeploy.exe, wsus.exe) or where the file path contains common installer directories (e.g., C:\Windows\Installer\, C:\ProgramData\Package Cache\, C:\Temp\).legacy_app_thin.exe)