This detection identifies potential Borland Delphi-based malware or legacy applications by analyzing file signatures that match the specific UPXFreak YARA rule pattern. A SOC team should proactively hunt for this in Azure Sentinel to uncover overlooked legacy software risks and distinguish benign Delphi artifacts from anomalous behavior that could indicate early-stage compromise.
rule UPXFreakv01BorlandDelphiHMX0101
{
meta:
author="malware-lu"
strings:
$a0 = { BE [4] 83 C6 01 FF E6 00 00 00 [3] 00 03 00 00 00 [4] 00 10 00 00 00 00 [4] 00 00 ?? F6 ?? 00 B2 4F 45 00 ?? F9 ?? 00 EF 4F 45 00 ?? F6 ?? 00 8C D1 42 00 ?? 56 ?? 00 [3] 00 [3] 00 [3] 00 ?? 24 ?? 00 [3] 00 }
$a1 = { BE [4] 83 C6 01 FF E6 00 00 00 [3] 00 03 00 00 00 [4] 00 10 00 00 00 00 [4] 00 00 ?? F6 ?? 00 B2 4F 45 00 ?? F9 ?? 00 EF 4F 45 00 ?? F6 ?? 00 8C D1 42 00 ?? 56 ?? 00 [3] 00 [3] 00 [3] 00 ?? 24 ?? 00 [3] 00 34 50 45 00 [3] 00 FF FF 00 00 ?? 24 ?? 00 ?? 24 ?? 00 [3] 00 40 00 00 C0 00 00 [4] 00 00 ?? 00 00 00 ?? 1E ?? 00 ?? F7 ?? 00 A6 4E 43 00 ?? 56 ?? 00 AD D1 42 00 ?? F7 ?? 00 A1 D2 42 00 ?? 56 ?? 00 0B 4D 43 00 ?? F7 ?? 00 ?? F7 ?? 00 ?? 56 ?? 00 [5] 00 00 00 [7] 77 [3] 00 [3] 00 [3] 77 [2] 00 00 [3] 00 [6] 00 00 [3] 00 [11] 00 [4] 00 00 00 00 [3] 00 }
condition:
$a0 at pe.entry_point or $a1 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 2 string patterns in its detection logic.
Here are 5 specific false positive scenarios for the UPXFreakv01BorlandDelphiHMX0101 YARA rule, which targets Borland Delphi-based executables often associated with legacy or embedded systems:
Legacy ERP Reporting Service Execution
ReportGen.exe process spawns from the C:\Program Files\LegacyERP\Bin directory, mimicking the signature of a known Borland artifact often flagged as suspicious in modern environments.C:\Program Files\LegacyERP\Bin\ReportGen.exe and hash the file to add its SHA-256 hash to the allow-list for this rule.Industrial SCADA HMI Application Startup
PlantMonitor_v4.exe, developed using Delphi 10.3, launches automatically on the engineering workstation. The YARA rule detects the embedded Borland runtime libraries within this executable as a potential anomaly due to the age of the compiler framework used in industrial control systems.PlantMonitor_v4.exe running under the user context DOMAIN\ENG-Admin, or filter by file path containing \SCADA\Apps\.Third-Party Barcode Scanner Utility
ZebraScanUtil.exe) written in Delphi to run on thin clients. When the utility initializes and connects to the database, it loads specific Borland DLLs that match the rule’s