This hunt targets adversaries deploying the kappfree.dll component of a Chinese hack tool suite to establish persistence or execute reconnaissance activities within Windows endpoints. Proactively hunting for this artifact in Azure Sentinel is critical because its low severity classification may cause it to be overlooked by automated alerts, allowing stealthy initial footholds to evolve into significant compromises before detection.
rule kappfree {
meta:
description = "Chinese Hacktool Set - file kappfree.dll"
author = "Florian Roth"
reference = "http://tools.zjqhr.com/"
date = "2015-06-13"
hash = "e57e79f190f8a24ca911e6c7e008743480c08553"
strings:
$s1 = "Bienvenue dans un processus distant" fullword wide
$s2 = "kappfree.dll" fullword ascii
$s3 = "kappfree de mimikatz pour Windows (anti AppLocker)" fullword wide
condition:
uint16(0) == 0x5a4d and filesize < 200KB and all of them
}
This YARA rule can be deployed in the following contexts:
This rule contains 3 string patterns in its detection logic.
Here are 5 specific false positive scenarios for the Chinese Hacktool Set - kappfree.dll detection rule in an enterprise environment:
Deployment of Third-Party “AppFree” Utility by IT Operations
kappfree.dll into the C:\Program Files\AppFree\Bin directory and registers it as a background service for system optimization, triggering the detection upon installation or first run.\AppFree\ AND the file hash matches the known good SHA-256 of the vendor-signed binary. Additionally, exclude events generated by the System or specific Service Accounts (e.g., svc-deployment) during standard maintenance windows.Execution via Scheduled Task for Regional Compliance Reporting
kappfree.dll to extract usage metrics from local applications, causing the detection logic to flag the DLL load as suspicious activity due to its association with Chinese tooling.TaskScheduler.exe (or svchost.exe running under the “Local Service” account) AND the command line arguments include a reference to the specific scheduled task name (Regional_Compliance_Scan).Software Installation via SCCM or Intune Management