HackTool - Quarks PwDump Execution

 Original Source: [Sigma source]
Title: HackTool - Quarks PwDump Execution
Status: test
Description:Detects usage of the Quarks PwDump tool via commandline arguments
References:
  -https://github.com/quarkslab/quarkspwdump
  -https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/seedworm-apt-iran-middle-east
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2022-09-05
modified:2023-02-05
Tags:
  • -'attack.credential-access'
  • -'attack.t1003.002'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
    Image|endswith: '\QuarksPwDump.exe'
  selection_cli:
    CommandLine:
      -' -dhl'
      -' --dump-hash-local'
      -' -dhdc'
      -' --dump-hash-domain-cached'
      -' --dump-bitlocker'
      -' -dhd '
      -' --dump-hash-domain '
      -'--ntds-file'

  condition:1 of selection_*
Falsepositives:
  -Unlikely
Level: high