This hunt targets adversaries deploying the datPcShare.exe component of a Chinese hacktool suite to establish persistent access and exfiltrate sensitive data within Azure environments. Proactively hunting for this specific artifact is critical because its legitimate appearance often masks low-severity, long-term reconnaissance activities that may evade standard alerting thresholds until significant compromise occurs.
rule datPcShare {
meta:
description = "Chinese Hacktool Set - file datPcShare.exe"
author = "Florian Roth"
reference = "http://tools.zjqhr.com/"
date = "2015-06-13"
hash = "87acb649ab0d33c62e27ea83241caa43144fc1c4"
strings:
$s1 = "PcShare.EXE" fullword wide
$s2 = "MZKERNEL32.DLL" fullword ascii
$s3 = "PcShare" fullword wide
$s4 = "QQ:4564405" fullword wide
condition:
uint16(0) == 0x5a4d and filesize < 500KB and all of them
}
This YARA rule can be deployed in the following contexts:
This rule contains 4 string patterns in its detection logic.
Here are 4 specific false positive scenarios for the Chinese Hacktool Set - file datPcShare.exe detection rule in an enterprise environment:
Deployment of “DatPcShare” by IT Asset Management Teams
datPcShare.exe as a background service for data synchronization and policy enforcement. This file is frequently executed during the initial agent installation or periodic configuration updates pushed via SCCM/Intune.a1b2c3...) and restrict the rule to trigger only if the file path is outside the standard installation directory (e.g., exclude paths under C:\Program Files\DatPcShare\ or C:\Windows\SystemApps\).Execution via Scheduled Task for Data Backup
datPcShare.exe to synchronize employee file shares with an on-premise Chinese cloud storage gateway. The execution is triggered by the system account (NT AUTHORITY\SYSTEM) rather than an interactive user session, which often bypasses standard user behavior baselines but triggers this specific file-based rule.TaskScheduler.exe (PID 104) and the User Account matches a known service account (e.g., svc_backup_sync). Additionally, filter for execution times strictly within the maintenance window (e.g., 01:30–0