← Back to SOC feed Coverage →

EXEStealthv272

yara LOW Yara-Rules
community
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at Yara-Rules →
Retrieved: 2026-09-12T11:00:00Z · Confidence: medium

Hunt Hypothesis

This rule targets the execution of potentially obfuscated or packed executables that may indicate stealthy malware deployment or fileless attack techniques. Proactively hunting for these indicators helps the SOC team identify low-fidelity threats that might evade standard signature-based detections, ensuring early visibility into suspicious binary activity within the Azure environment.

YARA Rule

rule EXEStealthv272
{
      meta:
		author="malware-lu"
strings:
		$a0 = { EB 00 EB 2F 53 68 61 72 65 77 61 72 65 20 2D 20 }

condition:
		$a0 at pe.entry_point
}

Deployment Notes

This YARA rule can be deployed in the following contexts:

This rule contains 1 string patterns in its detection logic.

False Positive Guidance

Original source: https://github.com/Yara-Rules/rules/blob/main/packers/packer.yar