This hunt targets adversaries deploying the PacketX.dll ActiveX wrapper to establish persistent network visibility and traffic analysis capabilities within Windows environments. Proactively hunting for this artifact in Azure Sentinel is critical because its presence often indicates early-stage reconnaissance by Chinese threat actors who leverage custom packet capture libraries to evade standard detection mechanisms.
rule dll_PacketX {
meta:
description = "Chinese Hacktool Set - file PacketX.dll - ActiveX wrapper for WinPcap packet capture library"
author = "Florian Roth"
reference = "http://tools.zjqhr.com/"
date = "2015-06-13"
score = 50
hash = "3f0908e0a38512d2a4fb05a824aa0f6cf3ba3b71"
strings:
$s9 = "[Failed to load winpcap packet.dll." wide
$s10 = "PacketX Version" wide
condition:
uint16(0) == 0x5a4d and filesize < 1920KB and all of them
}
This YARA rule can be deployed in the following contexts:
This rule contains 2 string patterns in its detection logic.
Here are 5 specific false positive scenarios for the Chinese Hacktool Set - file PacketX.dll detection rule, tailored for an enterprise environment:
Network Monitoring and Traffic Analysis Tools
PacketX.dll ActiveX wrapper to interface with WinPcap for real-time packet sniffing and traffic analysis, triggering the rule during routine health checks or bandwidth profiling.SolarWinds.Agent.exe, PRTGProbe.exe, Wireshark.exe) from generating alerts when accessing PacketX.dll.Endpoint Detection and Response (EDR) Packet Capture Modules
PacketX.dll as part of its ActiveX integration layer.C:\Program Files\CrowdStrike\fs.exe, MsMpEng.exe) and their scheduled diagnostic tasks that explicitly invoke packet capture libraries.Scheduled Database Performance Audits
PacketX.dll to capture and analyze network latency between the database engine and application tiers during peak maintenance windows