← Back to SOC feed Coverage →

SDProtectRandyLi

yara LOW Yara-Rules
community
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at Yara-Rules →
Retrieved: 2026-09-19T23:00:00Z · Confidence: medium

Hunt Hypothesis

This hypothesis targets the presence of the SDProtect RandyLi YARA signature, which indicates the execution or memory footprint of a specific low-severity malware variant or tooling component. Proactively hunting for this indicator allows the SOC team to identify dormant or stealthy implants in Azure Sentinel that may have bypassed initial perimeter defenses, ensuring early detection of potential lateral movement or data staging activities.

YARA Rule

rule SDProtectRandyLi
{
      meta:
		author="malware-lu"
strings:
		$a0 = { 55 8B EC 6A FF 68 [4] 68 88 88 88 08 64 A1 00 00 00 00 50 64 89 25 00 00 00 00 58 64 A3 00 00 00 00 58 58 58 58 8B E8 E8 3B 00 00 00 E8 01 00 00 00 FF 58 05 }

condition:
		$a0 at pe.entry_point
}

Deployment Notes

This YARA rule can be deployed in the following contexts:

This rule contains 1 string patterns in its detection logic.

False Positive Guidance

Original source: https://github.com/Yara-Rules/rules/blob/main/packers/packer.yar