Common Information
Type Value
Value
rule M_Hunting_3CXDesktopApp_Export {
	meta:
		disclaimer = "This rule is meant for hunting and is not tested to run in a production environment"
		description = "Detects an export used in 3CXDesktopApp malware"
		md5 = "7faea2b01796b80d180399040bb69835"
		date = "2023/03/31"
		version = "1"
	strings:
		$str1 = "DllGetClassObject" ascii wide
		$str2 = "3CXDesktopApp" ascii wide
	condition:
		all of ($str*)
}
Category
Type Yara Rule
Misp Type
Description
Details Published Attributes CTI Title
Details Website 2023-04-20 72 3CX Software Supply Chain Compromise Initiated by a Prior Software Supply Chain Compromise; Suspected North Korean Actor Responsible | Mandiant