This hunt aims to identify the presence of the XScanLib.dll artifact, a known component of the Chinese Hacktool set often associated with advanced persistent threat reconnaissance activities. Proactively hunting for this file in Azure Sentinel is critical because its low severity rating may cause it to be overlooked by standard alerting, allowing adversaries to establish a foothold before initiating more aggressive data exfiltration or lateral movement phases.
rule XScanLib {
meta:
description = "Chinese Hacktool Set - file XScanLib.dll"
author = "Florian Roth"
reference = "http://tools.zjqhr.com/"
date = "2015-06-13"
hash = "c5cb4f75cf241f5a9aea324783193433a42a13b0"
strings:
$s4 = "XScanLib.dll" fullword ascii
$s6 = "Ports/%s/%d" fullword ascii
$s8 = "DEFAULT-TCP-PORT" fullword ascii
$s9 = "PlugCheckTcpPort" fullword ascii
condition:
uint16(0) == 0x5a4d and filesize < 360KB and all of them
}
This YARA rule can be deployed in the following contexts:
This rule contains 4 string patterns in its detection logic.
Here are 4 specific false positive scenarios for the Chinese Hacktool Set - file XScanLib.dll detection rule, tailored for an enterprise environment:
Legitimate Deployment of Alibaba Cloud Security Agent
XScanLib.dll as a core component for real-time vulnerability scanning and asset discovery within the Chinese cloud ecosystem.C:\Program Files\Alibaba\CloudAssistant\*) or filter by the parent process name AliyunService.exe or AliYunDunAgent.exe.Execution of Tencent Cloud Security Center (Tencent PC Manager)
XScanLib.dll to perform deep system scans, registry checks, and malware signature updates during off-peak hours.C:\Program Files (x86)\Tencent\PCManager\* or filter by the parent process TencentPCManager.exe. Additionally, verify the file hash against the known good signature from the vendor’s release notes.Installation of 360 Total Security Enterprise Edition
XScanLib.dll as part of its heuristic scanning engine to detect local threats and system integrity issues.