← Back to SOC feed Coverage →

STProtectorV15SilentSoftware

yara LOW Yara-Rules
community
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at Yara-Rules →
Retrieved: 2026-08-30T23:00:00Z · Confidence: medium

Hunt Hypothesis

This detection identifies silent software installations by STProtector V15, a behavior often indicative of adversaries establishing persistence or deploying custom tools without triggering standard user notifications. Proactively hunting for this activity in Azure Sentinel allows the SOC team to uncover stealthy initial access or lateral movement attempts that might otherwise remain invisible due to their non-intrusive nature.

YARA Rule

rule STProtectorV15SilentSoftware
{
      meta:
		author="malware-lu"
strings:
		$a0 = { 00 00 00 00 4B 65 52 6E 45 6C 33 32 2E 64 4C 6C 00 00 47 65 74 50 72 6F 63 41 64 64 72 65 73 73 00 00 4C 6F 61 64 4C 69 62 72 61 72 79 41 00 00 }

condition:
		$a0
}

Deployment Notes

This YARA rule can be deployed in the following contexts:

This rule contains 1 string patterns in its detection logic.

False Positive Guidance

Here are 4 specific false positive scenarios for the STProtectorV15SilentSoftware detection rule, including targeted filters and exclusions:

Original source: https://github.com/Yara-Rules/rules/blob/main/packers/packer.yar