← Back to SOC feed Coverage →

PseudoSigner01ExeSmasherAnorganix

yara LOW Yara-Rules
community
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at Yara-Rules →
Retrieved: 2026-09-18T11:00:00Z · Confidence: medium

Hunt Hypothesis

This rule identifies potentially malicious executables that utilize the PseudoSigner01ExeSmasherAnorganix YARA signature, often associated with tools designed to obfuscate or manipulate binary structures to evade static analysis. Proactively hunting for this indicator in Azure Sentinel allows the SOC to detect low-severity, stealthy payloads that may be used for initial access or privilege escalation before they trigger more prominent behavioral alerts.

YARA Rule

rule PseudoSigner01ExeSmasherAnorganix
{
      meta:
		author="malware-lu"
strings:
		$a0 = { 9C FE 03 90 60 BE 90 90 41 90 8D BE 90 10 FF FF 57 83 CD FF EB 10 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 FE 0B E9 }

condition:
		$a0 at pe.entry_point
}

Deployment Notes

This YARA rule can be deployed in the following contexts:

This rule contains 1 string patterns in its detection logic.

False Positive Guidance

Original source: https://github.com/Yara-Rules/rules/blob/main/packers/packer.yar