← Back to SOC feed Coverage →

muckisprotectorIImucki

yara LOW Yara-Rules
community
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at Yara-Rules →
Retrieved: 2026-09-09T23:00:00Z · Confidence: medium

Hunt Hypothesis

This YARA rule targets the Mucki Protector II malware, a known tool used for process injection and memory protection to evade detection, indicating a potential foothold for advanced persistent threats. Proactively hunting for this signature in Azure Sentinel allows the SOC to identify compromised endpoints early, leveraging the low severity as an early warning signal to investigate lateral movement or privilege escalation attempts before they mature into high-impact incidents.

YARA Rule

rule muckisprotectorIImucki
{
      meta:
		author="malware-lu"
strings:
		$a0 = { E8 24 00 00 00 8B 4C 24 0C C7 01 17 00 01 00 C7 81 B8 00 00 00 00 00 00 00 31 C0 89 41 14 89 41 18 80 6A 00 E8 85 C0 74 12 64 8B 3D 18 00 00 00 8B 7F 30 0F B6 47 02 85 C0 74 01 C3 C7 04 24 [4] BE [4] B9 [4] 8A 06 F6 D0 88 06 46 E2 F7 C3 }

condition:
		$a0 at pe.entry_point
}

Deployment Notes

This YARA rule can be deployed in the following contexts:

This rule contains 1 string patterns in its detection logic.

False Positive Guidance

Original source: https://github.com/Yara-Rules/rules/blob/main/packers/packer.yar