← Back to SOC feed Coverage →

Armadillov410SiliconRealmsToolworks

yara LOW Yara-Rules
community
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at Yara-Rules →
Retrieved: 2026-09-16T23:00:00Z · Confidence: medium

Hunt Hypothesis

This YARA rule targets specific tooling artifacts associated with the Armadillo v410 variant, potentially indicating the presence of custom or obfuscated malware components within memory or on disk. Proactively hunting for these signatures allows the SOC team to identify low-severity, stealthy implantations that may serve as initial footholds or lateral movement tools before they escalate to higher-impact activities.

YARA Rule

rule Armadillov410SiliconRealmsToolworks
{
      meta:
		author="malware-lu"
strings:
		$a0 = { 55 8B EC 6A FF 68 F8 8E 4C 00 68 D0 EA 49 00 64 A1 00 00 00 00 50 64 89 25 00 00 00 00 83 EC 58 53 56 57 89 65 E8 FF 15 88 31 4C 00 33 D2 8A D4 89 15 7C A5 4C 00 8B C8 81 E1 FF 00 00 00 89 0D 78 A5 4C 00 C1 E1 08 03 CA 89 0D 74 A5 4C 00 C1 E8 10 A3 70 A5 }

condition:
		$a0 at pe.entry_point
}

Deployment Notes

This YARA rule can be deployed in the following contexts:

This rule contains 1 string patterns in its detection logic.

False Positive Guidance

Original source: https://github.com/Yara-Rules/rules/blob/main/packers/packer.yar