← Back to SOC feed Coverage →

ThemidaWinLicenseV1XNoCompressionSecureEngineOreansTechnologies

yara LOW Yara-Rules
community
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at Yara-Rules →
Retrieved: 2026-08-12T23:00:00Z · Confidence: medium

Hunt Hypothesis

This detection identifies the presence of the Themida WinLicense V1X secure engine with no compression, a signature often associated with legitimate software licensing mechanisms but potentially indicative of obfuscated malware or supply chain compromises. Proactively hunting for this specific artifact in Azure Sentinel allows the SOC team to distinguish between benign license enforcement and stealthy adversary activity that leverages commercial protection tools to evade standard heuristic analysis.

YARA Rule

rule ThemidaWinLicenseV1XNoCompressionSecureEngineOreansTechnologies
{
      meta:
		author="malware-lu"
strings:
		$a0 = { 8B C5 8B D4 60 E8 00 00 00 00 5D 81 ED [4] 89 95 [4] 89 B5 [4] 89 85 [4] 83 BD [5] 74 0C 8B E8 8B E2 B8 01 00 00 00 C2 0C 00 8B 44 24 24 89 85 [4] 6A 45 E8 A3 00 00 00 68 9A 74 83 07 E8 DF 00 00 00 68 25 4B 89 0A E8 D5 00 00 00 E9 [4] 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 }

condition:
		$a0
}

Deployment Notes

This YARA rule can be deployed in the following contexts:

This rule contains 1 string patterns in its detection logic.

False Positive Guidance

Here are 4 specific false positive scenarios for the ThemidaWinLicenseV1XNoCompressionSecureEngineOreansTechnologies detection rule, including targeted filters and exclusions:

Original source: https://github.com/Yara-Rules/rules/blob/main/packers/packer.yar