← Back to SOC feed Coverage →

nPackv11150200BetaNEOx

yara LOW Yara-Rules
community
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at Yara-Rules →
Retrieved: 2026-08-26T11:00:00Z · Confidence: medium

Hunt Hypothesis

This detection identifies the execution of a specific software package version (nPack v1.11.150200 Beta NEOx) via YARA signature matching to uncover potential unauthorized or legacy application deployments that may serve as an initial foothold for adversaries. Proactively hunting for this behavior in Azure Sentinel allows the SOC team to validate the legitimacy of these installations before they evolve into broader threats, ensuring early visibility into supply chain risks and unapproved software usage within the environment.

YARA Rule

rule nPackv11150200BetaNEOx
{
      meta:
		author="malware-lu"
strings:
		$a0 = { 83 3D 40 [3] 00 75 05 E9 01 00 00 00 C3 E8 41 00 00 00 B8 80 [3] 2B 05 08 [3] A3 3C [2] 00 E8 5E 00 00 00 E8 E0 01 00 00 E8 EC 06 00 00 E8 F7 05 00 00 }

condition:
		$a0 at pe.entry_point
}

Deployment Notes

This YARA rule can be deployed in the following contexts:

This rule contains 1 string patterns in its detection logic.

False Positive Guidance

Here are 4 specific false positive scenarios for the nPackv11150200BetaNEOx YARA rule detection, including suggested filters and exclusions tailored for an enterprise environment:

Original source: https://github.com/Yara-Rules/rules/blob/main/packers/packer.yar