This YARA rule identifies executable files packed with the RLPack v1.19 packer, a technique often used by adversaries to compress and obfuscate malicious payloads to evade static analysis. Proactively hunting for these packed binaries in Azure Sentinel helps detect low-severity threats that may be staging for execution or lateral movement, ensuring visibility into potentially obfuscated malware before it establishes a foothold.
rule RLPackV119DllLZMA430ap0x
{
meta:
author="malware-lu"
strings:
$a0 = { 80 7C 24 08 01 0F 85 C7 01 00 00 60 E8 00 00 00 00 8B 2C 24 83 C4 04 83 7C 24 28 01 75 0C 8B 44 24 24 89 85 49 0B 00 00 EB 0C 8B 85 45 0B 00 00 89 85 49 0B 00 00 8D B5 6D 0B 00 00 8D 9D 2F 03 00 00 33 FF 6A 40 68 00 10 00 00 68 00 20 0C 00 6A 00 FF 95 DA 0A 00 00 89 85 41 0B 00 00 E8 76 01 00 00 EB 20 60 8B 85 49 0B 00 00 FF B5 41 0B 00 00 FF 34 37 01 04 24 FF 74 37 04 01 04 24 FF D3 61 83 C7 08 83 3C 37 00 75 DA 83 BD 55 0B 00 00 00 74 0E 83 BD 59 0B 00 00 00 74 05 E8 D7 01 00 00 8D 74 37 04 53 6A 40 68 00 10 00 00 68 [4] 6A 00 FF 95 DA 0A 00 00 89 85 69 0B 00 00 5B 60 FF B5 41 0B 00 00 56 FF B5 69 0B 00 00 FF D3 61 8B B5 69 0B 00 00 8B C6 EB 01 40 80 38 01 75 FA 40 8B 38 03 BD 49 0B 00 00 83 C0 04 89 85 65 0B 00 00 E9 98 00 00 00 56 FF 95 D2 0A 00 00 89 85 61 0B 00 00 85 C0 0F 84 C8 00 00 00 8B C6 EB 5F 8B 85 65 0B 00 00 8B 00 A9 00 00 00 80 74 14 35 00 00 00 80 50 8B 85 65 0B 00 00 C7 00 20 20 20 00 EB 06 FF B5 65 0B 00 00 FF B5 61 0B 00 00 FF 95 D6 0A 00 00 85 C0 0F 84 87 00 00 00 89 07 83 C7 04 8B 85 65 0B 00 00 EB 01 40 80 38 00 75 FA 40 89 85 65 0B 00 00 66 81 78 02 00 80 74 A1 80 38 00 75 9C EB 01 46 80 3E 00 75 FA 46 40 8B 38 03 BD 49 0B 00 00 83 C0 04 89 85 65 0B 00 00 80 3E 01 0F 85 5F FF FF FF 68 00 40 00 00 68 [4] FF B5 69 0B 00 00 FF 95 DE 0A 00 00 68 00 40 00 00 68 00 20 0C 00 FF B5 41 0B 00 00 FF 95 DE 0A 00 00 E8 3D 00 00 00 E8 24 01 00 00 61 E9 [4] 61 C3 }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Legitimate Application Installer or Updater: Many commercial software installers (e.g., Adobe Creative Cloud, JetBrains Toolbox, or Visual Studio Installer) use LZMA compression to package their payloads within a single executable or DLL. If the rule scans running processes or loaded modules, it may flag these installers during a scheduled update or initial deployment.
setup.exe, install.exe, uninstall.exe) from specific vendor directories (e.g., C:\Program Files\Adobe\, C:\Program Files\JetBrains\) or exclude processes with a valid digital signature from trusted vendors (Adobe, JetBrains, Microsoft).Archival Utility Execution: Administrators or automated scripts frequently use tools like 7-Zip (7z.exe), WinRAR (WinRAR.exe), or P7ZIP to compress or extract archives using the LZMA algorithm. If the YARA rule is applied to file scanning or memory dumps, these utilities or the temporary files they generate during extraction/compression can trigger the detection.
7z.exe, WinRAR.exe, P7zip.exe) and their associated temporary directories (e.g., %TEMP%, %APPDATA%\7-Zip) from the scan scope, or whitelist files with the .7z or .rar extensions if the rule is file-based.Embedded Resource in Signed Libraries: Some third-party or custom .NET or C++ libraries embed LZMA-compressed resources (such as icons, help files, or configuration data) directly into their DLLs. If the rule performs a deep scan of loaded DLLs in memory or on disk, these legitimate signed libraries (e.g., liblzma.dll from XZ Utils, or custom internal libraries) may match the pattern.