← Back to SOC feed Coverage →

RJcrushv100

yara LOW Yara-Rules
community
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at Yara-Rules →
Retrieved: 2026-09-14T23:00:00Z · Confidence: medium

Hunt Hypothesis

This YARA rule targets the specific memory footprint or binary characteristics of the RJcrushv100 tool, which is often associated with low-severity reconnaissance or utility activities in the threat landscape. Proactively hunting for this signature allows the SOC to identify potentially benign or overlooked instances of this tool in use, ensuring that its presence is contextualized against known baselines to distinguish between legitimate operations and stealthy adversary staging.

YARA Rule

rule RJcrushv100
{
      meta:
		author="malware-lu"
strings:
		$a0 = { 06 FC 8C C8 BA [2] 03 D0 52 BA [2] 52 BA [2] 03 C2 8B D8 05 [2] 8E DB 8E C0 33 F6 33 FF B9 }

condition:
		$a0 at pe.entry_point
}

Deployment Notes

This YARA rule can be deployed in the following contexts:

This rule contains 1 string patterns in its detection logic.

False Positive Guidance

Original source: https://github.com/Yara-Rules/rules/blob/main/packers/packer.yar