This hunt targets adversaries deploying the HTTPSCANNER.EXE reconnaissance tool to map network infrastructure and identify potential entry points within the Azure environment. Proactively hunting for this specific artifact is critical because its presence often signals early-stage information gathering by threat actors associated with Chinese hacktool sets, allowing the SOC team to investigate lateral movement before more aggressive exploitation occurs.
rule HTTPSCANNER {
meta:
description = "Chinese Hacktool Set - file HTTPSCANNER.EXE"
author = "Florian Roth"
reference = "http://tools.zjqhr.com/"
date = "2015-06-13"
hash = "ae2929346944c1ea3411a4562e9d5e2f765d088a"
strings:
$s1 = "HttpScanner.exe" fullword wide
$s2 = "HttpScanner" fullword wide
condition:
uint16(0) == 0x5a4d and filesize < 3500KB and all of them
}
This YARA rule can be deployed in the following contexts:
This rule contains 2 string patterns in its detection logic.
Here are 5 specific false positive scenarios for the Chinese Hacktool Set - file HTTPSCANNER.EXE detection rule, tailored for an enterprise environment:
Scheduled Vulnerability Scans by Qualys or Tenable
HTTPSCANNER.EXE to perform routine port and service discovery on endpoints. This activity is triggered daily during off-hours by the central management console, not by user interaction.qualysagent.exe, tenable_agent_service.exe) or the User Account running the job (e.g., DOMAIN\svc-vuln-scan).Endpoint Protection Web Traffic Analysis by Sophos or Symantec
SophosService.exe or Symantec AntiVirus) during real-time protection updates.HTTPSCANNER.EXE.Automated Compliance Audits by Microsoft System Center Configuration Manager (SCCM)
HTTPSCANNER.EXE to verify the status of