← Back to SOC feed Coverage →

FSGv110EngdulekxtBorlandC1999

yara LOW Yara-Rules
community
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at Yara-Rules →
Retrieved: 2026-08-22T11:00:00Z · Confidence: medium

Hunt Hypothesis

This detection identifies potential legacy Borland C++ 1999 compiler artifacts or associated malware signatures within the environment using a specialized YARA rule. The SOC team should proactively hunt for these indicators to uncover dormant threats or unauthorized legacy software that may introduce vulnerabilities in the Azure Sentinel ecosystem.

YARA Rule

rule FSGv110EngdulekxtBorlandC1999
{
      meta:
		author="malware-lu"
strings:
		$a0 = { EB 02 CD 20 2B C8 68 80 [2] 00 EB 02 1E BB 5E EB 02 CD 20 68 B1 2B 6E 37 40 5B 0F B6 C9 }

condition:
		$a0 at pe.entry_point
}

Deployment Notes

This YARA rule can be deployed in the following contexts:

This rule contains 1 string patterns in its detection logic.

False Positive Guidance

Here are 5 specific false positive scenarios for the FSGv110EngdulekxtBorlandC1999 detection rule, which targets legacy Borland C++ 1999 artifacts often found in older enterprise applications:

Original source: https://github.com/Yara-Rules/rules/blob/main/packers/packer.yar