This hunt targets adversaries deploying the NaslLib.dll component associated with Chinese hacktools to establish persistent network monitoring capabilities within Azure Sentinel. Proactively searching for this file is critical because its presence often indicates early-stage reconnaissance or lateral movement by threat actors utilizing specialized tooling that may evade standard signature-based defenses.
rule dat_NaslLib {
meta:
description = "Chinese Hacktool Set - file NaslLib.dll"
author = "Florian Roth"
reference = "http://tools.zjqhr.com/"
date = "2015-06-13"
hash = "fb0d4263118faaeed2d68e12fab24c59953e862d"
strings:
$s1 = "nessus_get_socket_from_connection: fd <%d> is closed" fullword ascii
$s2 = "[*] \"%s\" completed, %d/%d/%d/%d:%d:%d - %d/%d/%d/%d:%d:%d" fullword ascii
$s3 = "A FsSniffer backdoor seems to be running on this port%s" fullword ascii
condition:
uint16(0) == 0x5a4d and filesize < 1360KB and all of them
}
This YARA rule can be deployed in the following contexts:
This rule contains 3 string patterns in its detection logic.
Here are 5 specific false positive scenarios for the Chinese Hacktool Set - file NaslLib.dll detection rule, tailored for an enterprise environment:
Antivirus or EDR Real-Time Scanning of Legacy Applications
NaslLib.dll from the application’s installation directory (C:\Program Files\ChineseApp\Bin) to verify its integrity against known malware signatures.C:\Program Files\ChineseApp\Bin\NaslLib.dll) and exclude the AV scanner process (e.g., csagent.exe, s1service.exe) from triggering this rule when accessing files within that directory.Scheduled Software Deployment via SCCM or Intune
NaslLib.dll, into a temporary staging folder (C:\Windows\CCMCache) before installation.ccmexec.exe (SCCM) or IntuneManagementExtension.exe and the destination path matches the known deployment cache directories.Development Environment Build Processes