This detection identifies the presence of the RLPack11 Basic Edition application package, which may indicate legitimate software deployment or potential supply chain compromise involving this specific component. A proactive hunt is recommended to validate the installation context and ensure that any unexpected occurrences are not indicative of unauthorized tooling or a stealthy adversary leveraging common administrative utilities for persistence.
rule RLPack11BasicEditionap0x
{
meta:
author="malware-lu"
strings:
$a0 = { 60 E8 00 00 00 00 8B 2C 24 83 C4 04 8D B5 4A 02 00 00 8D 9D 11 01 00 00 33 FF EB 0F FF 74 37 04 FF 34 37 FF D3 83 C4 08 83 C7 08 83 3C 37 00 75 EB 8D 74 37 04 53 6A 40 68 00 10 00 00 68 }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 3-5 specific false positive scenarios for the RLPack11BasicEditionap0x YARA rule, tailored for an enterprise environment:
Scenario: Legitimate execution of the Rapid7 InsightVM (formerly Nessus) agent during scheduled vulnerability scanning.
rapidscan.exe or nessuscli.exe process spawns a child process to unpack and analyze local configuration files, which matches the RLPack signature pattern.C:\Program Files\Rapid7\InsightVM\Agent\ and the command line contains arguments related to “scan” or “config”.Scenario: Automated deployment of Microsoft Endpoint Configuration Manager (SCCM) updates.
ccmsetup.exe) extracts compressed packages containing RLPack components for system health monitoring tools, triggering the detection on the extraction event.Rapid7Agent.msi or any process initiated by CcmExec.exe running under the SYSTEM account during business hours (08:00–18:00).Scenario: Execution of a custom PowerShell script for Active Directory user provisioning.
New-User-Provision.ps1) that utilizes the RLPack library to validate user permissions and generate reports, causing the YARA rule to match the script’s embedded binary payload.powershell.exe and the command line includes -ExecutionPolicy Bypass, restricted to specific “IT-Admin” service accounts (e.g