← Back to SOC feed Coverage →

PECryptv100v101

yara LOW Yara-Rules
community
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at Yara-Rules →
Retrieved: 2026-09-08T23:00:00Z · Confidence: medium

Hunt Hypothesis

This rule identifies Windows executables that have been packed or encrypted using the PECrypt v1.00 or v1.01 algorithms, a technique often employed by threat actors to obscure code structure and evade static analysis. Proactively hunting for these indicators in Azure Sentinel allows the SOC to detect potentially malicious or obfuscated binaries early in the kill chain, reducing the time required to investigate suspicious processes before they execute their intended payload.

YARA Rule

rule PECryptv100v101
{
      meta:
		author="malware-lu"
strings:
		$a0 = { E8 [4] 5B 83 EB 05 EB 04 52 4E 44 21 EB 02 CD 20 EB }

condition:
		$a0 at pe.entry_point
}

Deployment Notes

This YARA rule can be deployed in the following contexts:

This rule contains 1 string patterns in its detection logic.

False Positive Guidance

Original source: https://github.com/Yara-Rules/rules/blob/main/packers/packer.yar