← Back to SOC feed Coverage →

ASProtect v123 RC1

yara LOW Yara-Rules
community
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at Yara-Rules →
Retrieved: 2026-09-23T23:00:00Z · Confidence: medium

Hunt Hypothesis

This rule identifies the presence of ASProtect v123 RC1, a commercial packer frequently abused by threat actors to obfuscate malicious payloads and evade static analysis. Proactively hunting for this signature allows the SOC to uncover hidden malware or trojans that may have been deployed on endpoints, ensuring early detection of stealthy threats that rely on packing techniques to bypass initial security controls.

YARA Rule

rule ASProtect_v123_RC1: PEiD
{
    strings:
        $a = { 68 01 ?? ?? 00 E8 01 00 00 00 C3 C3 }
    condition:
        $a at pe.entry_point

}

Deployment Notes

This YARA rule can be deployed in the following contexts:

This rule contains 1 string patterns in its detection logic.

False Positive Guidance

Original source: https://github.com/Yara-Rules/rules/blob/main/packers/peid.yar