This detection identifies the presence of the specific malware signature “NsPack14byNorthStarLiuXingPing” within endpoint or network traffic to uncover potential initial access or lateral movement by an adversary utilizing this known threat actor’s tools. Although currently classified with low severity, proactively hunting for this indicator in Azure Sentinel allows the SOC team to validate its context and detect early-stage infections before they escalate into more critical incidents.
rule NsPack14byNorthStarLiuXingPing
{
meta:
author="malware-lu"
strings:
$a0 = { 8B DF 83 3F 00 75 0A 83 C7 04 B9 00 00 00 00 EB 16 B9 01 00 00 00 03 3B 83 C3 04 83 3B 00 74 2D 01 13 8B 33 03 7B 04 57 51 52 53 }
condition:
$a0
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 5 specific false positive scenarios for the NsPack14byNorthStarLiuXingPing detection rule, including suggested filters and exclusions tailored for an enterprise environment:
Scenario: Automated Software Deployment via SCCM/Intune
ccmsetup.exe (SCCM) or Microsoft.IntuneManagementAgent.exe. Add a filter to ignore alerts originating from the specific installation directory path: C:\Windows\CCM\Logs\ or C:\Program Files\Microsoft Intune Management Extension\.Scenario: Antivirus Engine Scanning of Compressed Archives
.zip, .7z, or .cab files in real-time. When these engines unpack archives to inspect contents, the extraction utility often utilizes a packing mechanism similar to NsPack14, triggering the YARA rule on the temporary extracted binary.MsMpEng.exe (Defender), rtvscan64.exe (Symantec), or csagent.exe (CrowdStrike). Additionally, exclude file paths located within temporary directories such as %TEMP%, C:\Windows\Temp\, and C:\ProgramData\Microsoft\Windows Defender\Scans\.Scenario: **Scheduled Backup Jobs Using 7-Zip or Win