← Back to SOC feed Coverage →

ACProtectv190gRiscosoftwareInc

yara LOW Yara-Rules
community
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at Yara-Rules →
Retrieved: 2026-08-25T23:00:00Z · Confidence: medium

Hunt Hypothesis

This detection identifies the execution of binaries protected by Riso Software’s ACProtect v190g, a technique often employed by adversaries to obfuscate malware and evade static analysis within Azure Sentinel. Proactively hunting for this behavior allows the SOC team to distinguish between legitimate application usage and potential threats leveraging advanced packing mechanisms that may bypass standard signature-based defenses.

YARA Rule

rule ACProtectv190gRiscosoftwareInc
{
      meta:
		author="malware-lu"
strings:
		$a0 = { 60 0F 87 02 00 00 00 1B F8 E8 01 00 00 00 73 83 04 24 06 C3 }

condition:
		$a0 at pe.entry_point
}

Deployment Notes

This YARA rule can be deployed in the following contexts:

This rule contains 1 string patterns in its detection logic.

False Positive Guidance

Here are 5 specific false positive scenarios for the ACProtectv190gRiscosoftwareInc detection rule, along with suggested filters or exclusions:

Original source: https://github.com/Yara-Rules/rules/blob/main/packers/packer.yar