This hypothesis posits that adversaries are deploying the klock.dll component of a Chinese hacktool suite to establish persistence or perform reconnaissance within Azure environments. Proactive hunting for this specific artifact is critical because its low-severity classification may cause it to be overlooked by automated alerts, allowing attackers to maintain a stealthy foothold before escalating their activities.
rule x64_klock {
meta:
description = "Chinese Hacktool Set - file klock.dll"
author = "Florian Roth"
reference = "http://tools.zjqhr.com/"
date = "2015-06-13"
hash = "44825e848bc3abdb6f31d0a49725bb6f498e9ccc"
strings:
$s1 = "Bienvenue dans un processus distant" fullword wide
$s2 = "klock.dll" fullword ascii
$s3 = "Erreur : le bureau courant (" fullword wide
$s4 = "klock de mimikatz pour Windows" fullword wide
condition:
uint16(0) == 0x5a4d and filesize < 907KB and all of them
}
This YARA rule can be deployed in the following contexts:
This rule contains 4 string patterns in its detection logic.
Here are 5 specific false positive scenarios for the Chinese Hacktool Set - file klock.dll detection rule, including suggested filters and exclusions:
Endpoint Protection Agent Updates via Windows Task Scheduler
klock.dll into the %ProgramFiles%\Kingsoft\KGuard directory and registers it as a kernel driver to monitor file system integrity during patch installation.C:\Program Files\Kingsoft\*, C:\Program Files\360\*) where the parent process is the Windows Task Scheduler (svchost.exe or TaskSchedulerService) and the file hash matches a known benign version of klock.dll.IT Admin Deployment via SCCM/Intune Script Execution
C:\Temp\Deploy folder. If the deployment package includes a Chinese localization tool or a specific hardware driver wrapper containing klock.dll, the rule triggers upon file creation and subsequent loading by the deployment agent (ccmexec.exe).ccmexec.exe (SCCM) or IntuneManagementExtension.exe and the file path contains standard deployment staging directories like \Temp\Deploy, \AppData\Local\Microsoft\EnterpriseContent, or specific network share paths used for software distribution.Legacy Chinese ERP Client Installation