← Back to SOC feed Coverage →

Armadillov285

yara LOW Yara-Rules
community
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at Yara-Rules →
Retrieved: 2026-09-05T23:00:00Z · Confidence: medium

Hunt Hypothesis

This rule detects the presence of the Armadillo v285 malware strain, a known threat actor tool often used for initial access or persistence in enterprise environments. Proactively hunting for this signature allows the SOC to identify compromised hosts early, minimizing the potential for lateral movement or data exfiltration before the adversary establishes a foothold.

YARA Rule

rule Armadillov285
{
      meta:
		author="malware-lu"
strings:
		$a0 = { 55 8B EC 6A FF 68 68 [3] 68 [4] 64 A1 [4] 50 64 89 25 [4] 83 EC 58 53 56 57 89 65 E8 FF 15 28 [3] 33 D2 8A D4 89 15 24 }

condition:
		$a0 at pe.entry_point
}

Deployment Notes

This YARA rule can be deployed in the following contexts:

This rule contains 1 string patterns in its detection logic.

False Positive Guidance

Original source: https://github.com/Yara-Rules/rules/blob/main/packers/packer.yar