YARA rule set related to the 3CX incident
2023-03-30 • Nextron Systems •
https://github.com/Neo23x0/signature-base/blob/master/yara/gen_mal_3cx_compromise_mar23.yar
Neo23x0's signature-base excerpt publishes YARA rules for malicious Windows and macOS samples associated with the North Korea-linked 3CX compromise. The rules detect malicious DLLs, decrypted payloads, compromised 3CX-signed binaries, MSI installers, and macOS applications using PE/Mach-O traits, file-size constraints, known hashes, certificate metadata, and byte patterns for payload execution. Detection logic includes VirtualProtect and ReadFile/MZ checks, RC4 key material, Base64/AES-related routines, GitHub IconStorages strings, and markers found in the malicious samples. The material is useful for detection engineering and hunting because it gives defenders concrete signatures to validate suspected 3CX supply-chain activity in endpoint and file telemetry.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | aa4e398b3bd8645016d8090ffc77d15… | 2023-03-30 | 2023-05-02 |
| HASH | c485674ee63ec8d4e8fde9800788175… | 2023-03-30 | 2023-04-28 |
| HASH | 7986bbaee8940da11ce089383521ab4… | 2023-03-30 | 2023-04-28 |
| HASH | dde03348075512796241389dfea5560… | 2023-03-29 | 2023-04-28 |
| HASH | fad482ded2e25ce9e1dd3d3ecc3227a… | 2023-03-29 | 2023-04-28 |
| HASH | 59e1edf4d82fae4978e97512b0331b7… | 2023-03-29 | 2023-04-28 |
| HASH | aa124a4b4df12b34e74ee7f6c683b2e… | 2023-03-29 | 2023-04-28 |
| HASH | b86c695822013483fa4e2dfdf712c5e… | 2023-03-29 | 2023-03-31 |
| HASH | 51079c7e549cbad25429ff98b6d6ca0… | 2023-03-30 | 2023-03-30 |
| HASH | ac99602999bf9823f221372378f95ba… | 2023-03-30 | 2023-03-30 |