← Back to SOC feed Coverage →

PCShrinkv040b

yara LOW Yara-Rules
community
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at Yara-Rules →
Retrieved: 2026-09-13T11:00:00Z · Confidence: medium

Hunt Hypothesis

This rule detects the presence of PCShrink, a legacy compression utility often exploited by adversaries to compress and obfuscate malicious payloads or exfiltrated data before transfer. Proactively hunting for this indicator in Azure Sentinel helps identify potential data staging or obfuscation activities that may indicate an adversary preparing for exfiltration or hiding artifacts within the environment.

YARA Rule

rule PCShrinkv040b
{
      meta:
		author="malware-lu"
strings:
		$a0 = { 9C 60 BD [4] 01 [5] FF [5] 6A ?? FF [5] 50 50 2D }

condition:
		$a0 at pe.entry_point
}

Deployment Notes

This YARA rule can be deployed in the following contexts:

This rule contains 1 string patterns in its detection logic.

False Positive Guidance

Original source: https://github.com/Yara-Rules/rules/blob/main/packers/packer.yar