← Back to SOC feed Coverage →

PEQuakev006byfORGAT

yara LOW Yara-Rules
community
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at Yara-Rules →
Retrieved: 2026-09-13T23:00:00Z · Confidence: medium

Hunt Hypothesis

This YARA rule targets specific characteristics of the PEQuake malware, a known threat often used for initial access or lateral movement, allowing analysts to identify compromised hosts based on static binary signatures. Proactively hunting for this indicator in Azure Sentinel helps the SOC team detect low-severity infections early, preventing potential escalation to more impactful post-exploitation activities within the environment.

YARA Rule

rule PEQuakev006byfORGAT
{
      meta:
		author="malware-lu"
strings:
		$a0 = { E8 A5 00 00 00 2D ?? 00 00 00 00 00 00 00 00 00 00 3D ?? 00 00 2D ?? 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 4A ?? 00 00 5B ?? 00 00 6E ?? 00 00 00 00 00 00 6B 45 72 4E 65 4C 33 32 2E 64 4C 6C 00 00 00 47 65 74 50 72 6F 63 41 64 }

condition:
		$a0
}

Deployment Notes

This YARA rule can be deployed in the following contexts:

This rule contains 1 string patterns in its detection logic.

False Positive Guidance

Original source: https://github.com/Yara-Rules/rules/blob/main/packers/packer.yar