← Back to SOC feed Coverage →

AHTeamEPProtector03fakekkryptor9kryptoraFEUERRADER

yara LOW Yara-Rules
community
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at Yara-Rules →
Retrieved: 2026-09-15T23:00:01Z · Confidence: medium

Hunt Hypothesis

This rule detects the presence of a specific YARA signature associated with the AHTeamEPProtector03fakekkryptor9kryptoraFEUERRADER artifact, which likely indicates the execution or persistence of a low-severity endpoint protection component or a known benign false positive. Proactively hunting for this signature allows the SOC team to validate the integrity of endpoint agents and distinguish between expected protective processes and potential masquerading malware that may be leveraging similar naming conventions to evade detection.

YARA Rule

rule AHTeamEPProtector03fakekkryptor9kryptoraFEUERRADER
{
      meta:
		author="malware-lu"
strings:
		$a0 = { 90 [46] 90 FF E0 60 E8 [4] 5E B9 00 00 00 00 2B C0 02 04 0E D3 C0 49 79 F8 41 8D 7E 2C 33 46 ?? 66 B9 }

condition:
		$a0 at pe.entry_point
}

Deployment Notes

This YARA rule can be deployed in the following contexts:

This rule contains 1 string patterns in its detection logic.

False Positive Guidance

Original source: https://github.com/Yara-Rules/rules/blob/main/packers/packer.yar