← Back to SOC feed Coverage →

PellesC28x45xPelleOrinius

yara LOW Yara-Rules
community
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at Yara-Rules →
Retrieved: 2026-09-15T23:00:01Z · Confidence: medium

Hunt Hypothesis

This hypothesis targets the presence of the Pelles C compiler, a lightweight C development environment often utilized by threat actors to compile custom malware payloads or exploit code directly on compromised hosts. Proactively hunting for this artifact in Azure Sentinel allows the SOC team to identify potential build environments or staging areas for malicious code generation, which may indicate an adversary preparing for execution or persistence despite the low severity rating.

YARA Rule

rule PellesC28x45xPelleOrinius
{
      meta:
		author="malware-lu"
strings:
		$a0 = { 55 89 E5 6A FF 68 [4] 68 [4] 64 FF 35 [4] 64 89 25 [4] 83 EC }

condition:
		$a0 at pe.entry_point
}

Deployment Notes

This YARA rule can be deployed in the following contexts:

This rule contains 1 string patterns in its detection logic.

False Positive Guidance

Original source: https://github.com/Yara-Rules/rules/blob/main/packers/packer.yar