← Back to SOC feed Coverage →

FSGv131Engdulekxt

yara LOW Yara-Rules
community
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at Yara-Rules →
Retrieved: 2026-08-22T11:00:00Z · Confidence: medium

Hunt Hypothesis

This detection identifies specific file artifacts matching the FSGv131Engdulekxt signature, which may indicate early-stage adversary activity involving known malicious binaries or scripts within the environment. Proactively hunting for this pattern in Azure Sentinel allows the SOC team to validate potential low-severity indicators before they escalate into broader incidents, ensuring comprehensive coverage of subtle threat signals that automated rules might overlook.

YARA Rule

rule FSGv131Engdulekxt
{
      meta:
		author="malware-lu"
strings:
		$a0 = { BB D0 01 40 00 BF 00 10 40 00 BE [3] 00 53 BB [3] 00 B2 80 A4 B6 80 FF D3 73 F9 33 C9 FF D3 73 16 33 C0 FF D3 73 23 B6 80 41 B0 10 FF D3 12 C0 73 FA 75 42 AA EB E0 E8 46 00 00 00 02 F6 83 D9 01 75 10 E8 38 00 00 00 EB 28 AC D1 E8 74 48 13 C9 EB }

condition:
		$a0 at pe.entry_point
}

Deployment Notes

This YARA rule can be deployed in the following contexts:

This rule contains 1 string patterns in its detection logic.

False Positive Guidance

Here are 5 specific false positive scenarios for the FSGv131Engdulekxt YARA rule, including suggested filters and exclusions:

Original source: https://github.com/Yara-Rules/rules/blob/main/packers/packer.yar