This hunt detects the execution of binaries packed with the UPX v10x protector, a technique often used by adversaries to obscure malicious payloads and evade static analysis. Proactively hunting for this behavior in Azure Sentinel is essential because low-severity detections can serve as early indicators of fileless attacks or supply chain compromises that might otherwise be overlooked during routine monitoring.
rule UPXProtectorv10x
{
meta:
author="malware-lu"
strings:
$a0 = { EB EC [4] 8A 06 46 88 07 47 01 DB 75 07 }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 5 specific false positive scenarios for the UPXProtectorv10x detection rule in an enterprise environment, including suggested filters and exclusions:
Scenario: Automated deployment of third-party security agents (e.g., CrowdStrike Falcon or Carbon Black) via SCCM/Intune.
C:\Program Files\CrowdStrike\csagent.exe where the UPX signature matches the vendor’s official build). Alternatively, exclude processes spawned by ccmsetup.exe or msiexec.exe when they launch these specific agents.Scenario: Execution of internal administrative PowerShell scripts packaged with UPX.
powershell.exe running under the context of a scheduled task named “Daily_Patch_Routine”.Scenario: Scheduled backup agents (e.g., Veeam or Acronis) performing incremental backups.