title: HackTool - PCHunter Execution id: fca949cc-79ca-446e-8064-01aa7e52ece5 status: test description: Detects suspicious use of PCHunter, a tool like Process Hacker to view and manipulate processes, kernel options and other low level stuff references: - https://web.archive.org/web/20231210115125/http://www.xuetr.com/ - https://www.crowdstrike.com/blog/falcon-overwatch-report-finds-increase-in-ecrime/ - https://www.hexacorn.com/blog/2018/04/20/kernel-hacking-tool-you-might-have-never-heard-of-xuetr-pchunter/ author: Florian Roth (Nextron Systems), Nasreddine Bencherchali date: 2022-10-10 modified: 2024-11-23 tags: - attack.execution - attack.discovery - attack.t1082 - attack.t1057 - attack.t1012 - attack.t1083 - attack.t1007 logsource: category: process_creation product: windows detection: selection_image: Image|endswith: - '\PCHunter64.exe' - '\PCHunter32.exe' selection_pe: - OriginalFileName: 'PCHunter.exe' - Description: 'Epoolsoft Windows Information View Tools' selection_hashes: Hashes|contains: - 'SHA1=5F1CBC3D99558307BC1250D084FA968521482025' - 'MD5=987B65CD9B9F4E9A1AFD8F8B48CF64A7' - 'SHA256=2B214BDDAAB130C274DE6204AF6DBA5AEEC7433DA99AA950022FA306421A6D32' - 'IMPHASH=444D210CEA1FF8112F256A4997EED7FF' - 'SHA1=3FB89787CB97D902780DA080545584D97FB1C2EB' - 'MD5=228DD0C2E6287547E26FFBD973A40F14' - 'SHA256=55F041BF4E78E9BFA6D4EE68BE40E496CE3A1353E1CA4306598589E19802522C' - 'IMPHASH=0479F44DF47CFA2EF1CCC4416A538663' condition: 1 of selection_* falsepositives: - Unlikely level: high