← Back to SOC feed Coverage →

EXE32Packv136

yara LOW Yara-Rules
community
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at Yara-Rules →
Retrieved: 2026-08-21T23:00:00Z · Confidence: medium

Hunt Hypothesis

This hunt hypothesis targets adversaries utilizing the EXE32Pack v136 packing technique to obfuscate executable files and evade signature-based detection. A SOC team should proactively hunt for this behavior in Azure Sentinel because packed executables often conceal malicious payloads that may bypass initial scanning, requiring deeper behavioral analysis to identify potential threats before they execute.

YARA Rule

rule EXE32Packv136
{
      meta:
		author="malware-lu"
strings:
		$a0 = { 3B C0 74 02 81 83 55 3B C0 74 02 81 83 53 3B C9 74 01 BC [4] 02 81 [7] 3B DB 74 01 BE 5D 8B D5 81 ED CC 8D 40 }

condition:
		$a0 at pe.entry_point
}

Deployment Notes

This YARA rule can be deployed in the following contexts:

This rule contains 1 string patterns in its detection logic.

False Positive Guidance

Here are 4 specific false positive scenarios for the EXE32Packv136 detection rule, along with targeted filtering strategies:

Original source: https://github.com/Yara-Rules/rules/blob/main/packers/packer.yar