This YARA rule targets specific binary artifacts associated with the RLPack118DllaPlib043ap0x signature, potentially indicating the presence of a low-severity packed executable or library component that may be used for initial access or payload delivery. Proactively hunting for this signature in Azure Sentinel allows the SOC team to identify dormant or stealthy threats that traditional behavioral detections might miss, ensuring early visibility into low-fidelity indicators across the environment.
rule RLPack118DllaPlib043ap0x
{
meta:
author="malware-lu"
strings:
$a0 = { 80 7C 24 08 01 0F 85 5C 01 00 00 60 E8 00 00 00 00 8B 2C 24 83 C4 ?? 8D B5 1A 04 00 00 8D 9D C1 02 00 00 33 FF E8 61 01 00 00 EB 0F FF 74 37 04 FF 34 37 FF D3 83 C4 ?? 83 C7 ?? 83 3C 37 00 75 EB 83 BD 06 04 00 00 00 74 0E 83 BD 0A 04 00 00 00 74 05 E8 D7 01 00 00 8D 74 37 04 53 6A ?? 68 [4] 68 [4] 6A ?? FF 95 A7 03 00 00 89 85 16 04 00 00 5B FF B5 16 04 00 00 56 FF D3 83 C4 ?? 8B B5 16 04 00 00 8B C6 EB 01 }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Scenario: A developer or DevOps engineer is running a local build pipeline that compiles C/C++ code using mingw-w64 or msvc toolchains, where the linker (link.exe) or compiler driver (cl.exe) temporarily loads a specific runtime library (e.g., libstdc++.dll or a custom static library) that matches the byte pattern of RLPack118DllaPlib043ap0x.
cl.exe, link.exe, nmake.exe, or msbuild.exe, and the file path contains \build\, \obj\, or \bin\Debug\.Scenario: An automated scheduled task (e.g., Task Scheduler job named “DailyBackup”) executes a proprietary backup utility (e.g., VeeamAgent.exe or AcronisBackup.exe) that loads a proprietary compression or encryption DLL (e.g., AcronisCrypto.dll) which has a known signature overlap with the YARA rule due to shared header structures or packing algorithms.
VeeamAgent.exe, AcronisBackup.exe, CommvaultClient.exe) and the loaded module path resides under C:\Program Files\ or C:\Program Files (x86)\ with a trusted publisher.Scenario: A legacy application (e.g., OracleClient.exe or SAPgui.exe) is launched by a service account for a nightly data sync job. The application loads a specific OLE DB provider or native library (e.g., msdasql.dll or sapdb.dll) that is packed or compiled in a way that triggers the `RLPack118