This hunt targets adversaries deploying the specific “ms10048-x86.exe” artifact from the Chinese Hacktool set, which often indicates early-stage reconnaissance or lateral movement activities within a network. Proactively hunting for this low-severity file in Azure Sentinel is critical to identify potential stealthy intrusions before they escalate into high-impact incidents that automated rules might overlook due to their benign classification.
rule ms10048_x86 {
meta:
description = "Chinese Hacktool Set - file ms10048-x86.exe"
author = "Florian Roth"
reference = "http://tools.zjqhr.com/"
date = "2015-06-13"
hash = "e57b453966e4827e2effa4e153f2923e7d058702"
strings:
$s1 = "[ ] Resolving PsLookupProcessByProcessId" fullword ascii
$s2 = "The target is most likely patched." fullword ascii
$s3 = "Dojibiron by Ronald Huizer, (c) [email protected] ." fullword ascii
$s4 = "[ ] Creating evil window" fullword ascii
$s5 = "%sHANDLEF_INDESTROY" fullword ascii
$s6 = "[+] Set to %d exploit half succeeded" fullword ascii
condition:
uint16(0) == 0x5a4d and filesize < 100KB and 4 of them
}
This YARA rule can be deployed in the following contexts:
This rule contains 6 string patterns in its detection logic.
Here are 5 specific false positive scenarios for the Chinese Hacktool Set - file ms10048-x86.exe detection rule, tailored for an enterprise environment:
Microsoft Office Deployment Toolkit (ODT) Updates
ms10048-x86.exe (or similar naming conventions from the Chinese Hacktool family used in regional builds) within the %TEMP% directory before launching the main installer (setup.exe).\Microsoft Office Deployment Tool\ or parent processes named ODT.exe and OfficeClickToRun.exe. Additionally, exclude files located in C:\Windows\Temp that are created by the SYSTEM account.Citrix Workspace App Installation/Updates
ms10048-x86.exe to handle specific driver installations or component registration tasks on Windows x86/x64 hybrid systems.CitrixWorkspaceApp.exe, CWAService.exe, or CtxInstallAgent.exe. You can also whitelist file hashes associated with known Citrix update packages if available in your threat intelligence feed.SCCM (Configuration Manager) Application Deployment
ccmexec.exe) may invoke a custom installation wrapper. If the organization uses a regional software stack or