This hunt targets adversaries deploying the lamescan3.exe reconnaissance tool to map network topology and identify vulnerable hosts within the Azure environment. Proactively searching for this artifact is critical because its presence often signals early-stage information gathering by Chinese threat actors that may precede more aggressive lateral movement or data exfiltration campaigns.
rule lamescan3 {
meta:
description = "Chinese Hacktool Set - file lamescan3.exe"
author = "Florian Roth"
reference = "http://tools.zjqhr.com/"
date = "2015-06-13"
hash = "3130eefb79650dab2e323328b905e4d5d3a1d2f0"
strings:
$s1 = "dic\\loginlist.txt" fullword ascii
$s2 = "Radmin.exe" fullword ascii
$s3 = "lamescan3.pdf!" fullword ascii
$s4 = "dic\\passlist.txt" fullword ascii
condition:
uint16(0) == 0x5a4d and filesize < 3740KB and all of them
}
This YARA rule can be deployed in the following contexts:
This rule contains 4 string patterns in its detection logic.
Here are 4 specific false positive scenarios for the Chinese Hacktool Set - file lamescan3.exe detection rule in an enterprise environment:
Scheduled Endpoint Security Scans by Third-Party AV
lamescan3.exe is spawned as a temporary scanning engine to analyze memory and file integrity.lamescan3.exe when the parent process is the specific AV service (e.g., TmEngineService.exe, KsGuardSvc.exe) AND the execution path matches the vendor’s installation directory (e.g., C:\Program Files\Kingsoft\Antivirus\).Automated Patch Management and Compliance Audits
lamescan3.exe is launched as part of this agent to scan local drives for unauthorized software installations and report back to the central console.ccmexec.exe or IvAgent.exe parent process during the defined maintenance window (e.g., 01:00 – 04:00 UTC).Regional HR Onboarding and Asset Provisioning Scripts