This detection identifies the presence of the Liu Xing Ping (NSPack) malware family by matching file signatures against a specialized YARA rule to uncover potential initial access or lateral movement activities. A proactive hunt is essential in Azure Sentinel to validate these low-severity alerts and determine if the identified artifacts represent benign software or an early-stage threat requiring deeper investigation before it escalates.
rule NSPack3xLiuXingPing
{
meta:
author="malware-lu"
strings:
$a0 = { 9C 60 E8 00 00 00 00 5D 83 ED 07 8D 85 [2] FF FF ?? 38 01 0F 84 ?? 02 00 00 ?? 00 01 }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 5 specific false positive scenarios for the NSPack3xLiuXingPing detection rule in an enterprise environment, along with recommended filters or exclusions:
Scenario: Deployment of Microsoft Office Updates via Configuration Manager (SCCM)
OfficeC2RClient.exe process often utilizes the NSPack packaging engine to distribute cumulative updates to endpoints. During the installation phase, it generates temporary package files that match the YARA signature for LiuXingPing components.C:\Program Files (x86)\Microsoft Configuration Manager\ccmexec.exe and the file path contains \Office\. Alternatively, add a rule condition to ignore events occurring between 01:00 and 05:00 local time on weekdays.Scenario: Execution of Antivirus Definition Updates by Trend Micro or Symantec
TmNetSvc.exe (Trend) or Symantec Endpoint Protection service runs its scheduled hourly scan, it extracts a signature file that triggers the detection logic.--update, --refresh, or --install.Scenario: Automated Backup Jobs using Veeam or Commvault
vrb.exe or Commvault’s cmdAgent.exe utilizes NSPack to compress and package data chunks before transmission. The rule detects the temporary staging files created during this compression process as potential LiuXingPing activity.