← Back to SOC feed Coverage →

PECompactv110b7

yara LOW Yara-Rules
community
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at Yara-Rules →
Retrieved: 2026-08-21T23:00:00Z · Confidence: medium

Hunt Hypothesis

This hunt detects the execution of potentially obfuscated or packed Portable Executable (PE) files that match the specific signature defined by the PECompactv110b7 YARA rule, which often indicates an adversary attempting to evade static analysis through compression or packing techniques. A SOC team should proactively hunt for these artifacts in Azure Sentinel because low-severity detections of packed binaries can serve as early indicators of sophisticated threats that may bypass initial signature-based defenses while hiding malicious payloads within legitimate-looking processes.

YARA Rule

rule PECompactv110b7
{
      meta:
		author="malware-lu"
strings:
		$a0 = { EB 06 68 [4] C3 9C 60 E8 02 [3] 33 C0 8B C4 83 C0 04 93 8B E3 8B 5B FC 81 EB 0F 60 40 ?? 87 DD 8B 85 9A 60 40 ?? 01 85 03 60 40 ?? 66 C7 85 ?? 60 40 ?? 90 90 01 85 92 60 40 ?? BB 14 }

condition:
		$a0 at pe.entry_point
}

Deployment Notes

This YARA rule can be deployed in the following contexts:

This rule contains 1 string patterns in its detection logic.

False Positive Guidance

Here are 5 specific false positive scenarios for the PECompactv110b7 detection rule, including suggested filters and exclusions:

Original source: https://github.com/Yara-Rules/rules/blob/main/packers/packer.yar