This hunt targets adversary behavior involving the deployment of caidao.exe, a known Chinese hacktool often utilized for reconnaissance or initial foothold establishment within networked environments. Proactively hunting for this artifact in Azure Sentinel is critical to identify potential early-stage intrusions from state-sponsored actors, even when the associated severity is low, ensuring that benign-looking tools are not overlooked as part of a broader attack chain.
rule ChinaChopper_caidao {
meta:
description = "Chinese Hacktool Set - file caidao.exe"
author = "Florian Roth"
reference = "http://tools.zjqhr.com/"
date = "2015-06-13"
hash = "056a60ec1f6a8959bfc43254d97527b003ae5edb"
strings:
$s1 = "Pass,Config,n{)" fullword ascii
$s2 = "phMYSQLZ" fullword ascii
$s3 = "\\DHLP\\." fullword ascii
$s4 = "\\dhlp\\." fullword ascii
$s5 = "SHAutoComple" fullword ascii
$s6 = "MainFrame" ascii
condition:
uint16(0) == 0x5a4d and filesize < 1077KB and all of them
}
This YARA rule can be deployed in the following contexts:
This rule contains 6 string patterns in its detection logic.
Here are 4 specific false positive scenarios for the Chinese Hacktool Set - caidao.exe detection rule in an enterprise environment:
Enterprise Asset Management Scans
caidao.exe as a lightweight agent to perform periodic hardware inventory and software compliance checks.TencentManagerService.exe, HuaweiAgent.exe) running from standard installation directories like C:\Program Files\Tencent\ or C:\ProgramData\360\.Scheduled Patch Deployment Jobs
caidao.exe to verify file integrity before applying updates.caidao.exe when executed by the System or NT AUTHORITY\Network Service account, specifically if the command line arguments contain known job identifiers (e.g., /task:PatchVerify) and originates from a trusted path like C:\Windows\System32\Tasks\.Third-Party Anti-Malware Scanning
caidao.exe as its core scanning engine. This file is frequently triggered during on-demand scans