This rule detects the execution of a known obfuscated or scrambled binary, often used by adversaries to hide malicious logic and evade static analysis during initial access or payload delivery. Proactively hunting for this signature in Azure Sentinel allows the SOC team to identify compromised endpoints or suspicious processes before they can establish persistence or execute further post-compromise actions.
rule UnnamedScrambler25Ap0ke
{
meta:
author="malware-lu"
strings:
$a0 = { 55 8B EC B9 0B 00 00 00 6A 00 6A 00 49 75 F9 51 53 56 57 B8 6C 3E 40 00 E8 F7 EA FF FF 33 C0 55 68 60 44 40 00 64 FF 30 64 89 20 BA 70 44 40 00 B8 B8 6C 40 00 E8 62 F3 FF FF 8B D8 85 DB 75 07 6A 00 E8 A1 EB FF FF BA E8 64 40 00 8B C3 8B 0D B8 6C 40 00 E8 37 D3 FF FF C7 05 BC 6C 40 00 0A 00 00 00 BB 68 6C 40 00 BE 90 6C 40 00 BF E8 64 40 00 B8 C0 6C 40 00 BA 04 00 00 00 E8 07 EC FF FF 83 3B 00 74 04 33 C0 89 03 8B D7 8B C6 E8 09 F3 FF FF 89 03 83 3B 00 0F 84 BB 04 00 00 B8 C0 6C 40 00 8B 16 E8 06 E2 FF FF B8 C0 6C 40 00 E8 24 E1 FF FF 8B D0 8B 03 8B 0E E8 D1 D2 FF FF 8B C7 A3 20 6E 40 00 8D 55 EC 33 C0 E8 0C D4 FF FF 8B 45 EC B9 1C 6E 40 00 BA 18 6E 40 00 }
condition:
$a0
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
0x25 or base64 encoding of specific API names) that matches the byte pattern of UnnamedScrambler25Ap0ke. This is common in older codebases that haven’t been refactored to use standard P/Invoke wrappers.
msbuild.exe, dotnet.exe, or vbc.exe (Visual Basic Compiler), or exclude specific known internal binaries by SHA256 hash if the application is signed by the internal CA.FalconSensor.exe, cb.exe, defender.exe) and the action is “Scan” or “Inspect”. Alternatively, exclude if the file extension is .docx, .xlsx, or .pptx and the process is a known office suite component.Convert::ToBase64String with a specific padding or character set) that coincidentally matches the YARA rule’s string pattern. This often happens during