YARA rule set related to the 3CX incident

2023-03-30 Nextron Systems

https://github.com/Neo23x0/signature-base/blob/master/yara/gen_mal_3cx_compromise_mar23.yar

Thumbnail for YARA rule set related to the 3CX incident

Neo23x0's signature-base excerpt publishes YARA rules for malicious Windows and macOS samples associated with the North Korea-linked 3CX compromise. The rules detect malicious DLLs, decrypted payloads, compromised 3CX-signed binaries, MSI installers, and macOS applications using PE/Mach-O traits, file-size constraints, known hashes, certificate metadata, and byte patterns for payload execution. Detection logic includes VirtualProtect and ReadFile/MZ checks, RC4 key material, Base64/AES-related routines, GitHub IconStorages strings, and markers found in the malicious samples. The material is useful for detection engineering and hunting because it gives defenders concrete signatures to validate suspected 3CX supply-chain activity in endpoint and file telemetry.

Indicators of Compromise

Type Value First Seen Last Seen
HASH aa4e398b3bd8645016d8090ffc77d15… 2023-03-30 2023-05-02
HASH c485674ee63ec8d4e8fde9800788175… 2023-03-30 2023-04-28
HASH 7986bbaee8940da11ce089383521ab4… 2023-03-30 2023-04-28
HASH dde03348075512796241389dfea5560… 2023-03-29 2023-04-28
HASH fad482ded2e25ce9e1dd3d3ecc3227a… 2023-03-29 2023-04-28
HASH 59e1edf4d82fae4978e97512b0331b7… 2023-03-29 2023-04-28
HASH aa124a4b4df12b34e74ee7f6c683b2e… 2023-03-29 2023-04-28
HASH b86c695822013483fa4e2dfdf712c5e… 2023-03-29 2023-03-31
HASH 51079c7e549cbad25429ff98b6d6ca0… 2023-03-30 2023-03-30
HASH ac99602999bf9823f221372378f95ba… 2023-03-30 2023-03-30

Related Reports

« Back