This rule identifies the presence of Thinstall-compressed executables, a common technique used by adversaries to obfuscate malware payloads and evade static analysis. Proactively hunting for these embedded signatures in Azure Sentinel helps detect potentially suspicious or legacy applications that may be hiding malicious code within compressed archives.
rule ThinstallEmbedded27172719Jitit
{
meta:
author="malware-lu"
strings:
$a0 = { 9C 60 E8 00 00 00 00 58 BB [4] 2B C3 50 68 [4] 68 [4] 68 [4] E8 C1 FE FF FF E9 97 FF FF FF CC CC 55 8B EC 83 C4 F4 FC 53 57 56 8B 75 08 8B 7D 0C C7 45 FC 08 00 00 00 33 DB BA 00 00 00 80 43 33 C0 E8 19 01 00 00 73 0E 8B 4D F8 E8 27 01 00 00 02 45 F7 AA EB E9 E8 04 01 00 00 0F 82 96 00 00 00 E8 F9 00 00 00 73 5B B9 04 00 00 00 E8 05 01 00 00 48 74 DE 0F 89 C6 00 00 00 E8 DF 00 00 00 73 1B 55 BD 00 01 00 00 E8 DF 00 00 00 88 07 47 4D 75 F5 E8 C7 00 00 00 72 E9 5D EB A2 B9 01 00 00 00 E8 D0 00 00 00 83 C0 07 89 45 F8 C6 45 F7 00 83 F8 08 74 89 E8 B1 00 00 00 88 45 F7 E9 7C FF FF FF B9 07 00 00 00 E8 AA 00 00 00 50 33 C9 B1 02 E8 A0 00 00 00 8B C8 41 41 58 0B C0 74 04 8B D8 EB 5E 83 F9 02 74 6A 41 E8 88 00 00 00 89 45 FC E9 48 FF FF FF E8 87 00 00 00 49 E2 09 8B C3 E8 7D 00 00 00 EB 3A 49 8B C1 55 8B 4D FC 8B E8 33 C0 D3 E5 E8 5D 00 00 00 0B C5 5D 8B D8 E8 5F 00 00 00 3D 00 00 01 00 73 14 3D FF 37 00 00 73 0E 3D 7F 02 00 00 73 08 83 F8 7F 77 04 41 41 41 41 56 8B F7 2B F0 F3 A4 5E E9 F0 FE FF FF 33 C0 EB 05 8B C7 2B 45 0C 5E 5F 5B C9 C2 08 00 }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Legitimate Application Deployment via Thinstall Compressors: Many enterprise applications (e.g., legacy ERP clients, specific CAD tools, or internal proprietary software) are distributed using Thinstall to reduce file size. When these applications are installed or updated via standard deployment tools like SCCM (System Center Configuration Manager) or Intune, the Thinstall stub may be embedded in the installer or the resulting executable, triggering the YARA rule during file creation or execution.
C:\Program Files\, C:\Program Files (x86)\) where the parent process is a known deployment agent (e.g., ccmsetup.exe, msiexec.exe, or IntuneManagementAgent.exe).Scheduled Maintenance Jobs for Compressed Binaries: Some organizations use Thinstall to compress large data processing scripts or custom utilities that run via Windows Task Scheduler (e.g., nightly log rotation, database backup scripts, or ETL jobs). If the YARA rule scans running processes or recently modified files, these scheduled tasks will trigger alerts when the compressed binary is executed or updated.
svchost.exe (specifically the Schedule service) or TaskScheduler related processes, and verify the file path matches known maintenance script directories (e.g., C:\Scripts\, C:\Maintenance\).Developer Build Artifacts in CI/CD Pipelines: In development environments, Jenkins, Azure DevOps, or GitHub Actions agents may compile or package internal tools using Thinstall as part of the build process. The YARA rule may detect the embedded stub in the build output artifacts before they are moved to production, causing false positives on build agent machines. *