← Back to SOC feed Coverage →

VIRUSIWormBagle

yara LOW Yara-Rules
community
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at Yara-Rules →
Retrieved: 2026-09-17T11:00:00Z · Confidence: medium

Hunt Hypothesis

This hypothesis targets the presence of the Bagle worm, a legacy Windows file-sharing worm that propagates via network shares and email attachments, often indicating a compromised host or an unpatched system in the environment. Proactively hunting for this signature allows the SOC to identify dormant or persistent infections that may have been missed by real-time detections, ensuring that known low-severity threats are contained before they can leverage lateral movement or establish footholds within the Azure network.

YARA Rule

rule VIRUSIWormBagle
{
      meta:
		author="malware-lu"
strings:
		$a0 = { 6A 00 E8 95 01 00 00 E8 9F E6 FF FF 83 3D 03 50 40 00 00 75 14 68 C8 AF 00 00 E8 01 E1 FF FF 05 88 13 00 00 A3 03 50 40 00 68 5C 57 40 00 68 F6 30 40 00 FF 35 03 50 40 00 E8 B0 EA FF FF E8 3A FC FF FF 83 3D 54 57 40 00 00 74 05 E8 F3 FA FF FF 68 E8 03 00 }

condition:
		$a0
}

Deployment Notes

This YARA rule can be deployed in the following contexts:

This rule contains 1 string patterns in its detection logic.

False Positive Guidance

Original source: https://github.com/Yara-Rules/rules/blob/main/packers/packer.yar