← Back to SOC feed Coverage →

PESpinv07Cyberbob

yara LOW Yara-Rules
community
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at Yara-Rules →
Retrieved: 2026-08-16T11:00:00Z · Confidence: medium

Hunt Hypothesis

This detection identifies the execution of the Cyberbob malware family via a specific YARA signature, signaling potential initial access or reconnaissance activities by an adversary leveraging this threat actor’s toolset. Proactive hunting for this indicator in Azure Sentinel is essential to uncover early-stage infections that may evade standard heuristic controls and prevent lateral movement before the low-severity alert escalates into a broader incident.

YARA Rule

rule PESpinv07Cyberbob
{
      meta:
		author="malware-lu"
strings:
		$a0 = { EB 01 68 60 E8 00 00 00 00 8B 1C 24 83 C3 12 81 2B E8 B1 06 00 FE 4B FD 82 2C 24 83 D5 46 00 0B E4 74 9E 75 01 C7 81 73 04 D7 7A F7 2F 81 73 19 77 00 43 B7 F6 C3 6B B7 00 00 F9 FF E3 C9 C2 08 00 A3 68 72 01 FF 5D 33 C9 41 E2 17 EB 07 EA EB 01 EB EB 0D FF }

condition:
		$a0 at pe.entry_point
}

Deployment Notes

This YARA rule can be deployed in the following contexts:

This rule contains 1 string patterns in its detection logic.

False Positive Guidance

Here are 5 specific false positive scenarios for the PESpinv07Cyberbob detection rule, along with recommended filters or exclusions tailored for an enterprise environment:

Original source: https://github.com/Yara-Rules/rules/blob/main/packers/packer.yar