← Back to SOC feed Coverage →

FreeJoiner 152 Stub engine 16 GlOFF additional

yara LOW Yara-Rules
community
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at Yara-Rules →
Retrieved: 2026-09-25T23:00:00Z · Confidence: medium

Hunt Hypothesis

This hypothesis targets the presence of FreeJoiner 152 stub engine artifacts, which are often associated with the initial stages of malware infection or process injection techniques that adversaries use to establish a foothold in memory. Proactively hunting for these specific YARA signatures in Azure Sentinel allows the SOC team to identify low-severity, potentially stealthy loader components before they progress to more impactful post-exploitation activities.

YARA Rule

rule FreeJoiner_152_Stub_engine_16_GlOFF_additional: PEiD
{
    strings:
        $a = { E8 46 FD FF FF 50 E8 0C 00 00 00 FF 25 08 20 40 00 FF 25 0C 20 40 00 FF 25 10 20 40 00 FF 25 14 20 40 00 FF 25 18 20 40 00 FF 25 1C 20 40 00 FF 25 20 20 40 00 FF 25 24 20 40 00 FF 25 28 20 40 00 FF 25 00 20 40 00 }
    condition:
        $a at pe.entry_point

}

Deployment Notes

This YARA rule can be deployed in the following contexts:

This rule contains 1 string patterns in its detection logic.

False Positive Guidance

Original source: https://github.com/Yara-Rules/rules/blob/main/packers/peid.yar