← Back to SOC feed Coverage →

EXEPACKv405v406

yara LOW Yara-Rules
community
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at Yara-Rules →
Retrieved: 2026-09-10T23:00:00Z · Confidence: medium

Hunt Hypothesis

This rule identifies executable files packed with specific versions of the EXEpacker, a technique adversaries often use to compress or obfuscate malware payloads to evade static analysis. Proactively hunting for these packed binaries in Azure Sentinel helps detect stealthy initial access or persistence mechanisms that may bypass standard signature-based detections.

YARA Rule

rule EXEPACKv405v406
{
      meta:
		author="malware-lu"
strings:
		$a0 = { 8C C0 05 [2] 0E 1F A3 [2] 03 06 [2] 8E C0 8B 0E [2] 8B F9 4F 8B F7 FD F3 A4 }

condition:
		$a0 at pe.entry_point
}

Deployment Notes

This YARA rule can be deployed in the following contexts:

This rule contains 1 string patterns in its detection logic.

False Positive Guidance

Original source: https://github.com/Yara-Rules/rules/blob/main/packers/packer.yar