This hunt detects the presence of the Liuxingping malware family, which is known for its ability to establish persistence and exfiltrate sensitive data through network channels. Proactively hunting for this signature in Azure Sentinel allows the SOC team to identify early-stage infections before they escalate into significant data breaches or lateral movement events within the cloud environment.
rule NsPack14Liuxingping
{
meta:
author="malware-lu"
strings:
$a0 = { 9C 60 E8 00 00 00 00 5D B8 [2] 40 00 2D [2] 40 00 }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 5 specific false positive scenarios for the NsPack14Liuxingping detection rule in an enterprise environment, along with targeted filtering strategies:
Scenario: Scheduled Antivirus Database Updates
NsPack signature during nightly automated definition updates. The update engine unpacks compressed payload archives that mimic the structural characteristics of the Liuxingping malware family.C:\Program Files\CrowdStrike\ or C:\ProgramData\Microsoft\Windows Defender\) when the parent process is identified as falconupdater.exe or MsMpEng.exe.Scenario: Software Deployment via SCCM/Intune
.msi or .cab packages containing nested archives. The YARA rule may flag these extraction activities as suspicious packing behavior similar to NsPack14Liuxingping.ccmsetup.exe, TaskHost.exe, or intune-management-agent-rt.exe and the file extension being scanned is .msi, .cab, or .zip.Scenario: Backup Agent Archive Creation