This rule detects the presence of the NsPack v3.1 NorthStar packer, a tool frequently used by threat actors to compress and obfuscate malicious payloads to evade static analysis. Proactively hunting for this signature in Azure Sentinel allows the SOC team to identify potentially compromised hosts or staged malware artifacts before they are executed or further propagated within the environment.
rule NsPackv31NorthStar
{
meta:
author="malware-lu"
strings:
$a0 = { 9C 60 E8 00 00 00 00 5D 83 ED 07 8D 9D [2] FF FF 8A 03 3C 00 74 10 8D 9D [2] FF FF 8A 03 3C 01 0F 84 42 02 00 00 C6 03 01 8B D5 2B 95 [2] FF FF 89 95 [2] FF FF 01 95 [2] FF FF 8D B5 [2] FF FF 01 16 60 6A 40 68 00 10 00 00 68 00 10 00 00 6A 00 }
$a1 = { 9C 60 E8 00 00 00 00 5D 83 ED 07 8D 9D [2] FF FF 8A 03 3C 00 74 10 8D 9D [2] FF FF 8A 03 3C 01 0F 84 42 02 00 00 C6 03 01 8B D5 2B 95 [2] FF FF 89 95 [2] FF FF 01 95 [2] FF FF 8D B5 [2] FF FF 01 16 60 6A 40 68 00 10 00 00 68 00 10 00 00 6A 00 FF 95 [2] FF FF 85 C0 0F 84 6A 03 00 00 89 85 [2] FF FF E8 00 00 00 00 5B B9 68 03 00 00 03 D9 50 53 E8 B1 02 00 00 61 8B 36 8B FD 03 BD [2] FF FF 8B DF 83 3F 00 75 0A 83 C7 04 B9 00 00 00 00 EB 16 B9 01 00 00 00 03 3B 83 C3 04 83 3B 00 74 36 01 13 8B 33 03 7B 04 57 51 52 53 FF B5 [2] FF FF FF B5 [2] FF FF 8B D6 8B CF 8B 85 [2] FF FF 05 AA 05 00 00 FF D0 5B 5A 59 5F 83 F9 00 74 05 83 C3 08 EB C5 68 00 80 00 00 6A 00 }
condition:
$a0 at pe.entry_point or $a1
}
This YARA rule can be deployed in the following contexts:
This rule contains 2 string patterns in its detection logic.
nsis-3.09-setup.exe installer or the makensis.exe compiler is executed during a developer workstation build or a CI/CD pipeline agent task to compile custom NSIS installers.
cmd.exe, powershell.exe, or bash.exe (for CI agents) and the file path contains \nsis\ or \makensis\. Alternatively, exclude if the process name is makensis.exe and the working directory matches the project build folder.Task Scheduler (svchost.exe with Task Scheduler service) or schtasks.exe and the executable name matches a known internal tool name (e.g., config_packer.exe).7-Zip or WinRAR plugin that integrates NSIS functionality to create self-extracting archives for software deployment packages.
7zFM.exe, WinRAR.exe, or WinRAR.exe and the child process name contains nsis or matches the specific packer binary name used by the plugin.jnidispatch.dll or a custom .dll) that embeds NSIS packing capabilities for on-the-fly resource extraction, triggering the YARA rule on the loaded module.
java.exe, `dotnet.exe