This detection identifies executable files packed with the UPX 0.20 version, a common technique adversaries use to compress malware binaries and evade static signature-based analysis. Proactively hunting for these packed executables in Azure Sentinel helps the SOC team uncover stealthy payloads that may be hiding in memory or on disk, reducing the risk of undetected compromise from obfuscated threats.
rule UPX_020_EXE: PEiD
{
strings:
$a = { 8C CB B9 00 00 BE 00 00 89 F7 1E A9 B5 80 8D 87 05 00 8E D8 05 00 00 8E C0 FD F3 A5 FC 2E 80 6C 13 10 73 E8 AF AD 0E 0E 0E 06 1F 07 16 68 00 00 BD FF FF F7 E1 93 CB 55 50 58 21 03 03 02 07 }
condition:
$a at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
EXCEL.EXE or WINWORD.EXE) or other major vendor software (e.g., chrome.exe, firefox.exe) that has been packed with UPX 020 to reduce file size.
C:\Program Files\Microsoft Office\, C:\Program Files (x86)\Google\Chrome\) or match against a known-good hash list for major enterprise applications.deploy_tool.exe, backup_agent.exe) developed by the internal DevOps or IT team, where the developer used UPX 020 to compress the executable for distribution across the network.
C:\InternalTools\, D:\DevOps\Utilities\) or exclude processes initiated by known service accounts (e.g., DOMAIN\svc-devops, DOMAIN\svc-itadmin).log_collector.exe, metrics_agent.exe) that is part of a monitoring stack (like Datadog, New Relic, or internal telemetry agents) which may be UPX-packed to minimize footprint.
DatadogAgent, NewRelicAgent) or exclude files in common agent installation directories (e.g., C:\ProgramData\Datadog\, C:\Program Files\New Relic\).setup.exe from