← Back to SOC feed Coverage →

ASProtectvIfyouknowthisversionpostonPEiDboardh2

yara LOW Yara-Rules
community
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at Yara-Rules →
Retrieved: 2026-08-13T23:00:00Z · Confidence: medium

Hunt Hypothesis

This detection identifies the presence of a specific version of the ASProtect executable protection tool, which is frequently utilized by threat actors to obfuscate malware and evade static analysis. A proactive hunt for this indicator in Azure Sentinel allows the SOC team to uncover potentially protected malicious binaries that may bypass standard signature-based defenses due to their packed nature.

YARA Rule

rule ASProtectvIfyouknowthisversionpostonPEiDboardh2
{
      meta:
		author="malware-lu"
strings:
		$a0 = { 90 60 E8 03 00 00 00 E9 EB 04 5D 45 55 C3 E8 01 00 00 00 EB 5D BB ED FF FF FF 03 DD 81 EB 00 [2] 00 80 7D 4D 01 75 0C 8B 74 24 28 83 FE 01 89 5D 4E 75 31 8D 45 53 50 53 FF B5 DD 09 00 00 8D 45 35 50 E9 82 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 }

condition:
		$a0
}

Deployment Notes

This YARA rule can be deployed in the following contexts:

This rule contains 1 string patterns in its detection logic.

False Positive Guidance

Here are 5 specific false positive scenarios for the ASProtect detection rule (ASProtectvIfyouknowthisversionpostonPEiDboardh2), along with targeted filters and exclusions:

Original source: https://github.com/Yara-Rules/rules/blob/main/packers/packer.yar