This rule detects the presence of the NeoLitev10 YARA signature, which identifies specific malicious or suspicious code patterns often associated with targeted intrusions or low-level persistence mechanisms. Proactively hunting for this indicator in Azure Sentinel allows the SOC team to uncover stealthy threats that may have evaded standard behavioral detections, ensuring early identification of compromised workloads or endpoints within the cloud environment.
rule NeoLitev10
{
meta:
author="malware-lu"
strings:
$a0 = { 8B 44 24 04 8D 54 24 FC 23 05 [4] E8 [4] FF 35 [4] 50 FF 25 }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
schtasks or a Windows Service. The script binary or its associated DLLs may match the YARA signature if the rule targets specific NeoLite version strings or memory patterns.
svchost.exe (if running as a service) or specific known service executables (e.g., MyAppService.exe) and the command line contains arguments like /backup, /optimize, or /compact.DevTeam or QA security group, or restrict the rule to only trigger if the NeoLite process is running outside of standard development directories (e.g., C:\Users\<dev>\Projects\ or D:\DevEnvs\).C:\Program Files\VendorApp\) and where the parent process is the vendor’s installer or updater executable (e.g., VendorUpdater.exe).