← Back to SOC feed Coverage →

PassLock2000v10EngMoonlightSoftware

yara LOW Yara-Rules
community
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at Yara-Rules →
Retrieved: 2026-09-03T11:00:00Z · Confidence: medium

Hunt Hypothesis

This YARA rule targets the PassLock 2000 v10 English Moonlight software, a credential management tool often deployed in enterprise environments to store and manage sensitive passwords. Proactively hunting for this signature helps the SOC identify potential unauthorized installations or specific versions of the tool that may be leveraged by adversaries to access stored credentials or indicate a specific software footprint within the Azure Sentinel environment.

YARA Rule

rule PassLock2000v10EngMoonlightSoftware
{
      meta:
		author="malware-lu"
strings:
		$a0 = { 55 8B EC 53 56 57 BB 00 50 40 00 66 2E F7 05 34 20 40 00 04 00 0F 85 98 00 00 00 E8 1F 01 00 00 C7 43 60 01 00 00 00 8D 83 E4 01 00 00 50 FF 15 F0 61 40 00 83 EC 44 C7 04 24 44 00 00 00 C7 44 24 2C 00 00 00 00 54 FF 15 E8 61 40 00 B8 0A 00 00 00 F7 44 24 }

condition:
		$a0 at pe.entry_point
}

Deployment Notes

This YARA rule can be deployed in the following contexts:

This rule contains 1 string patterns in its detection logic.

False Positive Guidance

Original source: https://github.com/Yara-Rules/rules/blob/main/packers/packer.yar