← Back to SOC feed Coverage →

PseudoSigner01LCCWin321xAnorganix

yara LOW Yara-Rules
community
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at Yara-Rules →
Retrieved: 2026-09-11T11:00:00Z · Confidence: medium

Hunt Hypothesis

This YARA rule targets the PseudoSigner01LCCWin321xAnorganix malware family, which leverages a pseudo-signature to masquerade as legitimate software and evade basic security controls on Windows endpoints. Proactively hunting for this indicator in Azure Sentinel allows the SOC team to identify compromised hosts that may be using this low-severity, signature-based evasion technique to establish persistence or execute malicious payloads before they progress to more impactful stages of the attack lifecycle.

YARA Rule

rule PseudoSigner01LCCWin321xAnorganix
{
      meta:
		author="malware-lu"
strings:
		$a0 = { 64 A1 01 00 00 00 55 89 E5 6A FF 68 [4] 68 9A 10 40 90 50 E9 }

condition:
		$a0 at pe.entry_point
}

Deployment Notes

This YARA rule can be deployed in the following contexts:

This rule contains 1 string patterns in its detection logic.

False Positive Guidance

Original source: https://github.com/Yara-Rules/rules/blob/main/packers/packer.yar