← Back to SOC feed Coverage →

yzpack112UsAr

yara LOW Yara-Rules
community
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at Yara-Rules →
Retrieved: 2026-09-09T11:00:00Z · Confidence: medium

Hunt Hypothesis

This YARA rule targets specific binary patterns or code structures that may indicate the presence of a low-severity, potentially obfuscated, or legacy software component within the environment. Proactively hunting for these signatures helps the SOC team identify unusual or dormant artifacts that could serve as footholds for lateral movement or persistence, ensuring that low-fidelity indicators are not overlooked in the Azure Sentinel telemetry.

YARA Rule

rule yzpack112UsAr
{
      meta:
		author="malware-lu"
strings:
		$a0 = { 5A 52 45 60 83 EC 18 8B EC 8B FC 33 C0 64 8B 40 30 78 0C 8B 40 0C 8B 70 1C AD 8B 40 08 EB 09 8B 40 34 83 C0 7C 8B 40 3C AB E9 [4] B4 09 BA 00 00 1F CD 21 B8 01 4C CD 21 40 00 00 00 50 45 00 00 4C 01 02 00 [4] 00 00 00 00 00 00 00 00 E0 00 [2] 0B 01 [4] 00 00 }

condition:
		$a0 at pe.entry_point
}

Deployment Notes

This YARA rule can be deployed in the following contexts:

This rule contains 1 string patterns in its detection logic.

False Positive Guidance

Original source: https://github.com/Yara-Rules/rules/blob/main/packers/packer.yar