← Back to SOC feed Coverage →

InnoSetupModulev109a

yara LOW Yara-Rules
community
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at Yara-Rules →
Retrieved: 2026-08-19T23:00:00Z · Confidence: medium

Hunt Hypothesis

This detection identifies the execution of Inno Setup installer modules (version 109a), which adversaries frequently leverage to deliver legitimate-looking payloads that may conceal malicious components or facilitate initial access. Proactive hunting for this behavior in Azure Sentinel is essential to distinguish between routine software deployments and potential supply chain attacks where attackers abuse trusted installers to establish a foothold within the environment.

YARA Rule

rule InnoSetupModulev109a
{
      meta:
		author="malware-lu"
strings:
		$a0 = { 55 8B EC 83 C4 C0 53 56 57 33 C0 89 45 F0 89 45 C4 89 45 C0 E8 A7 7F FF FF E8 FA 92 FF FF E8 F1 B3 FF FF 33 C0 }

condition:
		$a0 at pe.entry_point
}

Deployment Notes

This YARA rule can be deployed in the following contexts:

This rule contains 1 string patterns in its detection logic.

False Positive Guidance

Here are 5 specific false positive scenarios for the InnoSetupModulev109a detection rule, including recommended filters and exclusions:

Original source: https://github.com/Yara-Rules/rules/blob/main/packers/packer.yar