This detection targets adversaries deploying the specific racle.dll component of a Chinese hacktool suite to establish persistence or execute reconnaissance within Windows environments. Proactively hunting for this artifact in Azure Sentinel is critical because its low severity classification may cause it to be overlooked by automated alerts, allowing attackers to maintain a stealthy foothold before escalating their activities.
rule Ms_Viru_racle {
meta:
description = "Chinese Hacktool Set - file racle.dll"
author = "Florian Roth"
reference = "http://tools.zjqhr.com/"
date = "2015-06-13"
hash = "13116078fff5c87b56179c5438f008caf6c98ecb"
strings:
$s0 = "PsInitialSystemProcess @%p" fullword ascii
$s1 = "PsLookupProcessByProcessId(%u) Failed" fullword ascii
$s2 = "PsLookupProcessByProcessId(%u) => %p" fullword ascii
$s3 = "FirstStage() Loaded, CurrentThread @%p Stack %p - %p" fullword ascii
condition:
uint16(0) == 0x5a4d and filesize < 210KB and all of them
}
This YARA rule can be deployed in the following contexts:
This rule contains 4 string patterns in its detection logic.
Here are 4 specific false positive scenarios for the Chinese Hacktool Set - file racle.dll detection rule, including suggested filters and exclusions:
Oracle Database Patching via Oracle Universal Installer (OUI)
oracle.exe) or the Oracle Installer service extracts racle.dll to temporary directories (e.g., %TEMP%\OraInstall\...) as part of applying critical security patches or installing new database components. This is a legitimate deployment activity often performed by DBA teams using tools like Oracle Enterprise Manager or automated scripts via Ansible.oracle.exe (specifically with the path containing \Program Files\Oracle\) and the destination directory starts with %TEMP%\OraInstall. Additionally, exclude files created by the service account NT SERVICE\OracleService*.SAP NetWeaver Application Server Deployment
racle.dll when deploying Java stack updates or configuring the ABAP kernel. This often occurs during scheduled nightly jobs managed by Microsoft System Center Configuration Manager (SCCM) to push updates across the SAP cluster.sapinst.exe or sapcontrol.exe. Furthermore, add a path-based exclusion for files located within the standard SAP installation root: C:\Program Files\SAP* and subdirectories named usr\sap\*\SYS\exe.Third-Party Backup Agent Initialization (Veeam/Commvault)