← Back to SOC feed Coverage →

ASProtectSKE21xexeAlexeySolodovnikov

yara LOW Yara-Rules
community
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at Yara-Rules →
Retrieved: 2026-08-13T23:00:00Z · Confidence: medium

Hunt Hypothesis

This hunt detects the execution of binaries protected by the ASPack packing tool, specifically targeting variants associated with Alexey Solodovnikov that may be used to obscure malicious code from static analysis. A SOC team should proactively hunt for these instances in Azure Sentinel because packed executables often evade signature-based detection and can serve as a precursor to advanced threats like fileless malware or staged attacks within the environment.

YARA Rule

rule ASProtectSKE21xexeAlexeySolodovnikov
{
      meta:
		author="malware-lu"
strings:
		$a0 = { 90 60 E8 03 00 00 00 E9 EB 04 5D 45 55 C3 E8 01 00 00 00 EB 5D BB ED FF FF FF 03 DD 81 EB 00 [3] 80 7D 4D 01 75 0C 8B 74 24 28 83 FE 01 89 5D 4E 75 31 8D 45 53 50 53 FF B5 ED 09 00 00 8D 45 35 50 E9 82 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 }

condition:
		$a0
}

Deployment Notes

This YARA rule can be deployed in the following contexts:

This rule contains 1 string patterns in its detection logic.

False Positive Guidance

Here are 4 specific false positive scenarios for the ASProtectSKE21xexeAlexeySolodovnikov detection rule, along with targeted filters and exclusions:

Original source: https://github.com/Yara-Rules/rules/blob/main/packers/packer.yar