← Back to SOC feed Coverage →

DIETv144v145f

yara LOW Yara-Rules
community
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at Yara-Rules →
Retrieved: 2026-08-20T11:00:00Z · Confidence: medium

Hunt Hypothesis

This hunt hypothesis targets potential file-based threats identified by the DIETv144v145f YARA signature to detect specific malicious artifacts that may evade standard heuristic scans. Proactive hunting for this rule in Azure Sentinel is essential to uncover low-severity, targeted file anomalies early, ensuring comprehensive coverage of the attack surface before adversaries can establish persistence or execute further lateral movement.

YARA Rule

rule DIETv144v145f
{
      meta:
		author="malware-lu"
strings:
		$a0 = { F8 9C 06 1E 57 56 52 51 53 50 0E FC 8C C8 BA [2] 03 D0 52 }

condition:
		$a0 at pe.entry_point
}

Deployment Notes

This YARA rule can be deployed in the following contexts:

This rule contains 1 string patterns in its detection logic.

False Positive Guidance

Here are 3-5 specific false positive scenarios for the DIETv144v145f detection rule, tailored for a legitimate enterprise environment:

Original source: https://github.com/Yara-Rules/rules/blob/main/packers/packer.yar