← Back to SOC feed Coverage →

FSG131dulekxt

yara LOW Yara-Rules
community
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at Yara-Rules →
Retrieved: 2026-09-16T11:00:01Z · Confidence: medium

Hunt Hypothesis

This YARA rule targets specific file signatures associated with the FSG131dulekxt indicator, potentially identifying low-severity malware or suspicious artifacts that may have been dropped during initial access or lateral movement. Proactively hunting for these signatures in Azure Sentinel allows the SOC team to detect dormant or stealthy threats that evade standard behavioral detections, ensuring early identification of compromised assets before they escalate in severity.

YARA Rule

rule FSG131dulekxt
{
      meta:
		author="malware-lu"
strings:
		$a0 = { BE [3] 00 BF [3] 00 BB [3] 00 53 BB [3] 00 B2 80 }

condition:
		$a0 at pe.entry_point
}

Deployment Notes

This YARA rule can be deployed in the following contexts:

This rule contains 1 string patterns in its detection logic.

False Positive Guidance

Original source: https://github.com/Yara-Rules/rules/blob/main/packers/packer.yar