This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
HackTool - PCHunter Execution
Original Source:
[Sigma source]
Title:
HackTool - PCHunter Execution
Status:
test
Description:
Detects suspicious use of PCHunter, a tool like Process Hacker to view and manipulate processes, kernel options and other low level stuff
References:
-https://web.archive.org/web/20231210115125/http://www.xuetr.com/
-https://www.crowdstrike.com/blog/falcon-overwatch-report-finds-increase-in-ecrime/
-https://www.hexacorn.com/blog/2018/04/20/kernel-hacking-tool-you-might-have-never-heard-of-xuetr-pchunter/
Author:
Florian Roth (Nextron Systems), Nasreddine Bencherchali
Date:
2022-10-10
modified:
2024-11-23
Tags:
-'attack.execution'
-'attack.discovery'
-'attack.t1082'
-'attack.t1057'
-'attack.t1012'
-'attack.t1083'
-'attack.t1007'
Logsource:
category: process_creation
product: windows
Detection:
selection_image:
Image|endswith
:
-'\PCHunter64.exe'
-'\PCHunter32.exe'
selection_pe:
OriginalFileName
:
'PCHunter.exe'
Description
:
'Epoolsoft Windows Information View Tools'
selection_hashes:
Hashes|contains
:
-'SHA1=5F1CBC3D99558307BC1250D084FA968521482025'
-'MD5=987B65CD9B9F4E9A1AFD8F8B48CF64A7'
-'SHA256=2B214BDDAAB130C274DE6204AF6DBA5AEEC7433DA99AA950022FA306421A6D32'
-'IMPHASH=444D210CEA1FF8112F256A4997EED7FF'
-'SHA1=3FB89787CB97D902780DA080545584D97FB1C2EB'
-'MD5=228DD0C2E6287547E26FFBD973A40F14'
-'SHA256=55F041BF4E78E9BFA6D4EE68BE40E496CE3A1353E1CA4306598589E19802522C'
-'IMPHASH=0479F44DF47CFA2EF1CCC4416A538663'
condition
:
1 of selection_*
Falsepositives:
-Unlikely
Level:
high