← Back to SOC feed Coverage →

AnticrackSoftwareProtectorv109ACProtect

yara LOW Yara-Rules
community
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at Yara-Rules →
Retrieved: 2026-09-07T23:00:00Z · Confidence: medium

Hunt Hypothesis

This rule identifies the presence of ACProtect, a commercial software protection tool often used by adversaries to obfuscate malicious payloads and evade static analysis. Proactively hunting for this signature allows the SOC to detect potentially hidden or packed executables that may be leveraging commercial protection mechanisms to mask their true intent within the environment.

YARA Rule

rule AnticrackSoftwareProtectorv109ACProtect
{
      meta:
		author="malware-lu"
strings:
		$a0 = { 60 [8] 00 00 [12] E8 01 00 00 00 ?? 83 04 24 06 C3 [5] 00 }

condition:
		$a0 at pe.entry_point
}

Deployment Notes

This YARA rule can be deployed in the following contexts:

This rule contains 1 string patterns in its detection logic.

False Positive Guidance

Original source: https://github.com/Yara-Rules/rules/blob/main/packers/packer.yar