← Back to SOC feed Coverage →

themida1005httpwwworeanscom

yara LOW Yara-Rules
community
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at Yara-Rules →
Retrieved: 2026-09-06T11:00:01Z · Confidence: medium

Hunt Hypothesis

This rule detects the presence of Themida-protected executables, a common anti-debugging and obfuscation technique frequently employed by malware authors to evade static analysis and dynamic inspection. Proactively hunting for these signatures in Azure Sentinel helps identify potentially compromised endpoints or malicious payloads that may be hiding in plain sight, allowing the SOC to investigate suspicious binaries before they execute their intended payload.

YARA Rule

rule themida1005httpwwworeanscom
{
      meta:
		author="malware-lu"
strings:
		$a0 = { B8 00 00 00 00 60 0B C0 74 58 E8 00 00 00 00 58 05 43 00 00 00 80 38 E9 75 03 61 EB 35 E8 00 00 00 00 58 25 00 F0 FF FF 33 FF 66 BB 19 5A 66 83 C3 34 66 39 18 75 12 0F B7 50 3C 03 D0 BB E9 44 }

condition:
		$a0 at pe.entry_point
}

Deployment Notes

This YARA rule can be deployed in the following contexts:

This rule contains 1 string patterns in its detection logic.

False Positive Guidance

Original source: https://github.com/Yara-Rules/rules/blob/main/packers/packer.yar