← Back to SOC feed Coverage →

EXECryptor224StrongbitSoftCompleteDevelopmenth3

yara LOW Yara-Rules
community
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at Yara-Rules →
Retrieved: 2026-08-17T23:00:00Z · Confidence: medium

Hunt Hypothesis

This hunt detects the execution of a specific executable associated with StrongBit Software’s development environment, potentially indicating legitimate software deployment or an adversary leveraging trusted application processes to establish persistence. A proactive search in Azure Sentinel is recommended to distinguish this benign activity from potential masquerading attacks where threat actors mimic known development tools to evade initial detection and execute malicious payloads within the organization’s infrastructure.

YARA Rule

rule EXECryptor224StrongbitSoftCompleteDevelopmenth3
{
      meta:
		author="malware-lu"
strings:
		$a0 = { 6B 65 72 6E 65 6C 33 32 2E 64 6C 6C 00 00 00 00 00 00 47 65 74 4D 6F 64 75 6C 65 48 61 6E 64 6C 65 41 00 00 00 00 4C 6F 61 64 4C 69 62 72 61 72 79 41 00 00 00 00 47 65 74 50 72 6F 63 41 64 64 72 65 73 73 00 00 00 00 00 00 45 78 69 74 50 72 6F 63 65 73 73 }

condition:
		$a0
}

Deployment Notes

This YARA rule can be deployed in the following contexts:

This rule contains 1 string patterns in its detection logic.

False Positive Guidance

Original source: https://github.com/Yara-Rules/rules/blob/main/packers/packer.yar