← Back to SOC feed Coverage →

WinZip32bit6x

yara LOW Yara-Rules
community
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at Yara-Rules →
Retrieved: 2026-08-22T11:00:00Z · Confidence: medium

Hunt Hypothesis

This detection identifies the execution of 32-bit or 64-bit WinZip processes to uncover potential adversary use of legitimate compression tools for payload delivery or data exfiltration. SOC teams should proactively hunt for this activity in Azure Sentinel to distinguish between routine administrative usage and suspicious instances where attackers leverage trusted applications to bypass security controls.

YARA Rule

rule WinZip32bit6x
{
      meta:
		author="malware-lu"
strings:
		$a0 = { FF 15 FC 81 40 00 B1 22 38 08 74 02 B1 20 40 80 38 00 74 10 }

condition:
		$a0 at pe.entry_point
}

Deployment Notes

This YARA rule can be deployed in the following contexts:

This rule contains 1 string patterns in its detection logic.

False Positive Guidance

Here are 5 specific false positive scenarios for the WinZip32bit6x detection rule, including suggested filters and exclusions:

Original source: https://github.com/Yara-Rules/rules/blob/main/packers/packer.yar