This hunt targets adversary activity involving the deployment of the specific Chinese hacktool artifact CookieTools2.exe, which is often utilized for credential harvesting and session manipulation within compromised endpoints. Proactively hunting for this file in Azure Sentinel allows the SOC team to identify early-stage reconnaissance or lateral movement attempts by threat actors leveraging region-specific tooling before they escalate into higher-severity incidents.
rule CookieTools2 {
meta:
description = "Chinese Hacktool Set - file CookieTools2.exe"
author = "Florian Roth"
reference = "http://tools.zjqhr.com/"
date = "2015-06-13"
hash = "cb67797f229fdb92360319e01277e1345305eb82"
strings:
$s1 = "www.gxgl.com&www.gxgl.net" fullword wide
$s2 = "ip.asp?IP=" fullword ascii
$s3 = "MSIE 5.5;" fullword ascii
$s4 = "SOFTWARE\\Borland\\" fullword ascii
condition:
uint16(0) == 0x5a4d and filesize < 700KB and all of them
}
This YARA rule can be deployed in the following contexts:
This rule contains 4 string patterns in its detection logic.
Here are 4 specific false positive scenarios for the Chinese Hacktool Set - CookieTools2.exe detection rule, tailored for an enterprise environment:
Automated Browser Maintenance via Group Policy
CookieTools2.exe to clear browser cache and session cookies for compliance auditing before the start of the business week.gpupdate.exe or TaskSchedulerService, combined with a specific Hash Exclusion for the known good version of CookieTools2.exe deployed by IT.Third-Party Remote Support Sessions (LogMeIn/TeamViewer)
CookieTools2.exe to manage user session cookies and ensure secure handshakes between the agent and the host.-session-mode or -remote-trigger) indicating an automated support launch rather than a user-initiated interactive session.CI/CD Pipeline Artifact Deployment
CookieTools2.exe to validate web application cookie persistence and configuration integrity immediately after pushing updates to the staging environment.