← Back to SOC feed Coverage →

PGMPACKv013

yara LOW Yara-Rules
community
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at Yara-Rules →
Retrieved: 2026-09-08T11:00:00Z · Confidence: medium

Hunt Hypothesis

This YARA rule targets specific memory patterns or code structures associated with the PGMPACKv013 packer, indicating the presence of packed executables that may be used to obscure malicious payloads or legitimate software in memory. Proactively hunting for these signatures in Azure Sentinel helps identify potentially obfuscated processes that could evade traditional static analysis, allowing the SOC to detect early-stage fileless or packed malware activity before it executes further malicious actions.

YARA Rule

rule PGMPACKv013
{
      meta:
		author="malware-lu"
strings:
		$a0 = { FA 1E 17 50 B4 30 CD 21 3C 02 73 ?? B4 4C CD 21 FC BE [2] BF [2] E8 [2] E8 [2] BB [2] BA [2] 8A C3 8B F3 }

condition:
		$a0 at pe.entry_point
}

Deployment Notes

This YARA rule can be deployed in the following contexts:

This rule contains 1 string patterns in its detection logic.

False Positive Guidance

Original source: https://github.com/Yara-Rules/rules/blob/main/packers/packer.yar