logo

Creating YARA Rules Based on Code

ID: 9b086806-6532-5995-9a60-afc4efba8d02

STIX ID: report--9b086806-6532-5995-9a60-afc4efba8d02

Feed Name: Binary Defense Blog

Threat Score
50/100

Date Published: 2025-08-12

Date Updated: 2026-04-27

...
...

This blog post demonstrates how to create YARA hex-string rules to detect the Echelon .NET stealer (SHA256 b52d4177277851b95c5cdf08bf2e3261c7ac80af449da00741c83bcf6c181d67). It explains hexadecimal strings, wildcards and jumps, inspecting MSIL with dnSpy, and provides example hex signatures and a sample YARA rule while warning the rule is based on a single sample and not production-ready.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.