← Back to SOC feed Coverage →

ASPack 108

yara LOW Yara-Rules
community
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at Yara-Rules →
Retrieved: 2026-09-24T23:00:00Z · Confidence: medium

Hunt Hypothesis

This rule identifies executable files packed with the ASPack 108 compression algorithm, a technique frequently used by threat actors to reduce binary size and evade static analysis during initial access or lateral movement. Proactively hunting for these packed binaries in Azure Sentinel allows the SOC to uncover hidden payloads or trojans that may have been deployed on endpoints, ensuring that compressed malware is detected before it can execute or propagate within the environment.

YARA Rule

rule ASPack_108: PEiD
{
    strings:
        $a = { 90 90 90 75 01 90 E9 }
    condition:
        $a at pe.entry_point

}

Deployment Notes

This YARA rule can be deployed in the following contexts:

This rule contains 1 string patterns in its detection logic.

False Positive Guidance

Original source: https://github.com/Yara-Rules/rules/blob/main/packers/peid.yar