This hypothesis targets the presence of the RLPack full edition packer, which adversaries frequently use to compress and obfuscate malicious payloads to evade static analysis. Proactively hunting for this specific YARA signature in Azure Sentinel allows the SOC to identify potentially packed executables early in the kill chain, reducing the risk of undetected malware execution or persistence.
rule RLPackFullEdition117LZMAAp0x
{
meta:
author="malware-lu"
strings:
$a0 = { 60 E8 00 00 00 00 8B 2C 24 83 C4 04 [15] 8D B5 73 26 00 00 8D 9D 58 03 00 00 33 FF [10] 6A 40 68 [4] 68 [4] 6A }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
RLPack command-line utility to compress a large log archive or build artifact for transfer, specifically using the LZMA algorithm and the “Full Edition” feature set.
cmd.exe, powershell.exe, bash) and the command line arguments contain rlpack and lzma, provided the process runs from a standard development or tools directory (e.g., C:\Tools\rlpack\ or C:\Users\<User>\AppData\Local\rlpack\).rlpack to optimize the size of a deployment package before uploading it to an artifact repository.
jenkins.exe, vstsagent.exe, github-actions-runner.exe) or the working directory matches the standard CI/CD workspace paths (e.g., C:\Jenkins\workspace\, C:\agent\work\).rlpack to compress daily backup files or application logs before moving them to cold storage.
schtasks.exe or Task Scheduler where the command line includes rlpack and the target path is within a known backup or log directory (e.g., C:\Backups\, C:\Logs\, D:\Archive\).