← Back to SOC feed Coverage →

TPACKv05cm2

yara LOW Yara-Rules
community
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at Yara-Rules →
Retrieved: 2026-08-27T23:00:00Z · Confidence: medium

Hunt Hypothesis

This detection identifies potential file-based threats by matching artifacts against the specific YARA signature defined in TPACKv05cm2, which may indicate known malware or suspicious application behavior within the environment. Proactively hunting for this signal allows the SOC team to validate low-severity alerts that could represent early-stage compromises or benign false positives, ensuring comprehensive coverage of file integrity and reducing the risk of undetected lateral movement in Azure Sentinel.

YARA Rule

rule TPACKv05cm2
{
      meta:
		author="malware-lu"
strings:
		$a0 = { 68 [2] FD 60 BE [2] BF [2] B9 [2] F3 A4 8B F7 BF [2] FC 46 E9 CE FD }

condition:
		$a0 at pe.entry_point
}

Deployment Notes

This YARA rule can be deployed in the following contexts:

This rule contains 1 string patterns in its detection logic.

False Positive Guidance

Here are 4 specific false positive scenarios for the TPACKv05cm2 detection rule, including suggested filters and exclusions tailored for a legitimate enterprise environment:

Original source: https://github.com/Yara-Rules/rules/blob/main/packers/packer.yar