This detection identifies executable files packed with the UPX utility, a technique frequently employed by adversaries to obscure malicious code and evade signature-based analysis. A proactive hunt for these artifacts in Azure Sentinel is essential because UPX-packed binaries often indicate early-stage fileless attacks or obfuscated payloads that may bypass standard static scanning mechanisms.
rule UPX072
{
meta:
author="malware-lu"
strings:
$a0 = { 60 E8 00 00 00 00 83 CD FF 31 DB 5E }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 5 specific false positive scenarios for the UPX072 detection rule, which identifies executables packed with the UPX utility:
Scenario: Deployment of Microsoft Office Updates via SCCM
Office suite. These update installers are frequently compressed using UPX to reduce bandwidth usage during distribution across the enterprise network.ccmsetup.exe or wuauserv.exe located in C:\Program Files (x86)\Microsoft Intune Management Extension\ or C:\Windows\System32\, specifically targeting .exe files with UPX headers during business hours (09:00–17:00).Scenario: Execution of Third-Party Antivirus Signature Updates
\Program Files\CrowdStrike\ or \SentinelOne\SentinelOneAgent\ and the process name matches falcon.sys or s1agent.exe.Scenario: Scheduled Backup Jobs Using Veeam Agent