← Back to SOC feed Coverage →

ASProtect13321RegisteredAlexeySolodovnikov

yara LOW Yara-Rules
community
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at Yara-Rules →
Retrieved: 2026-08-18T11:00:00Z · Confidence: medium

Hunt Hypothesis

This detection identifies the execution of a legitimate software component protected by ASProtect 13321, specifically associated with Alexey Solodovnikov, which may indicate normal application usage or potential supply chain compromise if observed in unexpected contexts. The SOC team should proactively hunt for this signature within Azure Sentinel to establish a baseline of trusted behavior and quickly distinguish between benign operations and adversaries leveraging known legitimate binaries to evade detection.

YARA Rule

rule ASProtect13321RegisteredAlexeySolodovnikov
{
      meta:
		author="malware-lu"
strings:
		$a0 = { 68 01 [3] E8 01 00 00 00 C3 C3 }

condition:
		$a0 at pe.entry_point
}

Deployment Notes

This YARA rule can be deployed in the following contexts:

This rule contains 1 string patterns in its detection logic.

False Positive Guidance

Here are 5 specific false positive scenarios for the ASProtect13321RegisteredAlexeySolodovnikov detection rule, tailored for an enterprise environment:

Original source: https://github.com/Yara-Rules/rules/blob/main/packers/packer.yar