This rule detects the presence of the PROPACKv208 YARA signature, which identifies specific malicious or suspicious code patterns often associated with low-severity threats or early-stage infection artifacts. Proactively hunting for this indicator allows the SOC team to identify potential footholds or dormant payloads in Azure Sentinel that may not yet trigger high-severity alerts, enabling early containment before lateral movement occurs.
rule PROPACKv208
{
meta:
author="malware-lu"
strings:
$a0 = { 8C D3 8E C3 8C CA 8E DA 8B 0E [2] 8B F1 83 [2] 8B FE D1 ?? FD F3 A5 53 }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
7zFM.exe or 7zG.exe) during a routine backup or archive creation task. The PROPACK packer is frequently used in older versions of 7-Zip or specific build configurations, causing the binary to match the YARA signature.
explorer.exe or a scheduled task service (svchost.exe with Schedule service) and the file path contains \Program Files\7-Zip\ or \Program Files (x86)\7-Zip\.C:\Program Files\Adobe\ or C:\Program Files (x86)\Adobe\ where the parent process is msiexec.exe, setup.exe, or Adobe Creative Cloud Helper.exe.vmtoolsd.exe or vmware-user-sandbox-wrapper) on virtualized workstations, particularly in older VMware Workstation or ESXi guest environments where certain binaries are packed with PROPACK for optimization.
C:\Program Files\VMware\VMware Tools\ or /usr/bin/vmtoolsd (on Linux guests) where the parent process is vmware-usbarbitrator64.exe or the service vmtoolsd.WinRAR.exe or `