This rule detects the presence of the Petite packer, a tool frequently used by adversaries to compress and obfuscate malicious executables to evade static analysis and signature-based detection. Proactively hunting for this indicator in Azure Sentinel allows the SOC team to identify potentially hidden payloads within endpoint memory or disk, uncovering stealthy malware that may have bypassed initial perimeter defenses.
rule Petite14c199899IanLuck
{
meta:
author="malware-lu"
strings:
$a0 = { 66 9C 60 50 8B D8 03 00 68 54 BC 00 00 6A 00 FF 50 14 8B CC 8D A0 54 BC 00 00 50 8B C3 8D 90 ?? 16 00 00 68 00 00 [2] 51 50 80 04 24 08 50 80 04 24 42 50 80 04 24 61 50 80 04 24 9D 50 80 04 24 BB 83 3A 00 0F 84 D8 14 00 00 8B 44 24 18 F6 }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
C:\Program Files (x86)\, C:\Program Files\) or specific known legacy application paths (e.g., C:\Program Files (x86)\Adobe\). Additionally, consider whitelisting executables with valid digital signatures from trusted vendors.C:\Users\<username>\AppData\Local\, C:\Users\<username>\Documents\) on developer or build server roles. Alternatively, maintain a whitelist of specific internal tool names (e.g., internal_build_tool.exe) or exclude processes running from the C:\builds\ or C:\dev\ directories.code.exe, idea64.exe, chrome.exe) or exclude files located in plugin/extension directories (e.g., C:\Users\<username>\.vscode\extensions\, C:\Users\<username>\AppData\Local\Google\Chrome\User Data\).