This detection identifies the presence of the ASDPack20asd packing tool within file artifacts, signaling potential adversary activity to obfuscate malicious payloads or establish persistence through custom packaging mechanisms. SOC teams should proactively hunt for this signature in Azure Sentinel to uncover stealthy threats that evade standard heuristic scans by leveraging specialized YARA rules against archived or compressed executables.
rule ASDPack20asd
{
meta:
author="malware-lu"
strings:
$a0 = { 00 00 00 00 [4] 00 00 00 00 00 00 00 00 [8] 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [4] 00 00 00 00 4B 65 72 6E 65 6C 33 32 2E 64 6C 6C 00 8D 49 00 1F 01 47 65 74 4D 6F 64 75 6C 65 48 61 6E 64 6C 65 41 00 90 }
$a1 = { 5B 43 83 7B 74 00 0F 84 08 00 00 00 89 43 14 E9 }
$a2 = { 8B 44 24 04 56 57 53 E8 CD 01 00 00 C3 00 00 00 00 00 00 00 00 00 00 00 00 00 10 00 00 00 }
condition:
$a0 or $a1 or $a2 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 3 string patterns in its detection logic.
Here are 4 specific false positive scenarios for the ASDPack20asd detection rule, including suggested filters and exclusions tailored for an enterprise environment:
Scenario: Scheduled Antivirus Definition Updates
ASDPack20asd rule often triggers when the update service extracts compressed archives containing signature databases, mistaking the extraction process for a suspicious packing activity.MsMpEng.exe (Defender) or Symantec Antivirus Console.exe. Additionally, filter by file path: exclude files located in C:\ProgramData\Microsoft\Windows Defender\Platform\<version>\.Scenario: Software Deployment via SCCM/Intune
.msi or .cab packages to install applications. The YARA rule detects the temporary extraction of these deployment payloads as a potential “ASD Pack” activity, generating high-volume noise during maintenance windows.ccmsetup.exe, CcmExec.exe, or IntuneManagementExtension.exe from triggering this specific rule.Scenario: Automated Backup and Archive Jobs