This detection identifies the presence of the Liu Xing Ping malware variant within the environment by leveraging a specific YARA signature to scan for known malicious artifacts. Proactive hunting is essential in Azure Sentinel because this low-severity indicator often represents an early-stage infection that could escalate into lateral movement or data exfiltration if not identified and isolated before it spreads across the network.
rule NsPackV13LiuXingPing
{
meta:
author="malware-lu"
strings:
$a0 = { 9C 60 E8 00 00 00 00 5D B8 B3 85 40 00 2D AC 85 40 00 }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 5 specific false positive scenarios for the NsPackV13LiuXingPing detection rule, including targeted filters and exclusions:
Scenario: Automated Deployment of Microsoft Office Updates via SCCM/Intune
ccmexec.exe or Microsoft.Insights.Agent) extracts Office update packages containing the “LiuXingPing” signature pattern. This often triggers when large .msi or .appx payloads are unpacked on client machines.ccmexec.exe, Microsoft.Insights.Agent.exe, or MsMpEng.exe (Windows Defender) and the file path resides within the standard update cache directories (e.g., C:\Windows\SoftwareDistribution\Download or C:\ProgramData\Microsoft\Intune).Scenario: Execution of Third-Party Antivirus Signature Updates
NsPack packing algorithm used in the LiuXingPing detection logic.FalconSensor.exe, SoneAgent.exe, rtvscan64.exe) when they are accessing files within their specific installation directories (e.g., C:\Program Files\CrowdStrike\ or C:\ProgramData\SentinelOne\).Scenario: Scheduled Backup and Archiving Jobs using 7-Zip or WinRAR