← Back to SOC feed Coverage →

PeCompact 2xx Slim Loader BitSum Technologies additional

yara LOW Yara-Rules
community
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at Yara-Rules →
Retrieved: 2026-09-26T11:00:00Z · Confidence: medium

Hunt Hypothesis

This rule identifies the presence of BitSum Technologies’ PeCompact 2xx Slim Loader, a common executable compression tool that adversaries frequently use to reduce the size of malware payloads and evade basic static analysis. Proactively hunting for this specific loader in Azure Sentinel allows the SOC to detect potentially obfuscated binaries early in the kill chain, ensuring that compressed executables are inspected for hidden malicious code before they can execute or spread across the environment.

YARA Rule

rule PeCompact_2xx_Slim_Loader_BitSum_Technologies_additional: PEiD
{
    strings:
        $a = { B8 ?? ?? ?? 02 50 64 FF 35 00 00 00 00 64 89 25 00 00 00 00 33 C0 89 08 50 45 43 6F 6D 70 61 63 74 32 00 }
    condition:
        $a at pe.entry_point

}

Deployment Notes

This YARA rule can be deployed in the following contexts:

This rule contains 1 string patterns in its detection logic.

False Positive Guidance

Original source: https://github.com/Yara-Rules/rules/blob/main/packers/peid.yar