This hunt investigates the presence of epathobj_exp64.exe, a known component of the Chinese Hacktool suite often associated with advanced persistent threat reconnaissance and lateral movement activities. Proactively searching for this artifact in Azure Sentinel is critical to identify early-stage adversary footholds that may evade standard signature-based detections due to their legitimate tooling origins.
rule epathobj_exp64 {
meta:
description = "Chinese Hacktool Set - file epathobj_exp64.exe"
author = "Florian Roth"
reference = "http://tools.zjqhr.com/"
date = "2015-06-13"
hash = "09195ba4e25ccce35c188657957c0f2c6a61d083"
strings:
$s1 = "Watchdog thread %d waiting on Mutex" fullword ascii
$s2 = "Exploit ok run command" fullword ascii
$s3 = "\\epathobj_exp\\x64\\Release\\epathobj_exp.pdb" fullword ascii
$s4 = "Alllocated userspace PATHRECORD () %p" fullword ascii
$s5 = "Mutex object did not timeout, list not patched" fullword ascii
$s6 = "- inconsistent onexit begin-end variables" fullword wide /* Goodware String - occured 96 times */
condition:
uint16(0) == 0x5a4d and filesize < 150KB and 2 of them
}
This YARA rule can be deployed in the following contexts:
This rule contains 6 string patterns in its detection logic.
Here are 5 specific false positive scenarios for the Chinese Hacktool Set detection rule regarding epathobj_exp64.exe, along with suggested filters or exclusions:
Scenario: Deployment of Enterprise Antivirus (ESET) via Group Policy
epathobj_exp64.exe is a core component of the ESET Endpoint Security suite, specifically used for real-time protection and object scanning. In large enterprises, this executable often triggers when the central management server pushes updates or re-registers services to workstations via Group Policy (GPO) or SCCM during business hours.gpupdate.exe, ccmexec.exe (SCCM), or msiexec.exe, and the file path resides within the standard ESET installation directory (e.g., C:\Program Files\ESET\ESET Security\egui\).Scenario: Scheduled System Maintenance and Log Rotation
epathobj_exp64.exe with elevated privileges, it will generate file creation or execution events that mimic the behavior of a hacktool scanning system objects.TaskName: ESET_Daily_Scan) and the execution time falls within the defined maintenance window (e.g., 02:00 – 04:00 local time).Scenario: Third-Party Patch Management Execution