SUSP_Characteristics_ProcessDump_Nov22_2

Rule Info

Author
Florian Roth
Reference
Internal Research
Minimum Yara
3.0.0
Name
SUSP_Characteristics_ProcessDump_Nov22_2
Date
2022-11-01
Description
Detects programs with characteristics of process dumpers (capability to dump processes and write a .dmp file)
Tags
['HKTL', 'SUSP']
Score
65
Modified
2022-11-02
Av Ratio
3.54
Required Modules
[]
Rule Hash
53d3f7ead2f96e5f05a2cf8e9948dcf4

Antivirus Verdicts

Rating
Number of Samples
Malicious (>= 10 engines)
1
Suspicious (< 10 engines)
14
Clean (0 engines)
6

Rule Matches

Hash
Positives
Total
Timestamp
VT
94af68087ff51e2f82ae895aedf4aad542bde90e2e252b4f63cabaefa542c941
17
68
2022-11-30 04:13:20
22db298ba495a1274eb183654e31f8d1a18122fae5eb251b7e4d66531556b04a
2
72
2022-11-25 09:55:02
2515c143de0da8c31c5bf3bc9b6bbf54a7b7b437f855eae36cf0c37ef226499b
0
72
2022-11-25 08:26:58
26cf7fa988fff8968fb1957c85b64f2c8d5c5397d8f66a5acba88b941418b0cc
1
71
2022-11-19 07:24:19
887b8f717553a52fe4353e7c30285fb695fd4c2c0982f719a74df92dd30bb5d8
0
71
2022-11-19 03:21:27
32ae72604cd28ddd68bb53932e392dd5578076a761172ec65a3ebfbd01991b05
5
71
2022-11-19 01:29:44
37fe957e953a41776d435599bbc154b19f2fb562a6af90c8cb22ac5d5668207e
1
72
2022-11-18 10:21:00
cfeeeef92d7936f69f507a44b320a78fd0e1cb2e2b7f076f30d3e8f4f47f59f9
0
70
2022-11-18 10:08:47
ff02c342524f9058f268066c9464593c2353a8f2fa151938f1075909bdbadf5d
0
72
2022-11-18 05:17:22
35cfe6cf9e79c5f165d50c3a67eb3bf866f68e83d5d62bf575f81eef612d1f1e
3
70
2022-11-18 00:21:04
0a0a9c34edcfdc23da127a4785eadd7b09819e7b34e604cb49e235c98300bc27
6
62
2022-11-17 13:10:08
77fbb4c75df6ac0ef322245041a94110f0835dfbb6af09b2c4b52174c1dc6108
1
70
2022-11-17 12:30:52
709bfffe6ab3c6c9755437d8bc9432fadf4001d41677589ee89c911492a581f1
0
69
2022-11-17 08:09:23
119a5bb7c8c7b87d87f423981a0e1066d7dcada11943264a6007434becb7c409
0
70
2022-11-16 17:28:51
476faa8af68d693c61dffbac0e6d8fbe15d638172954cd85c957bebee6ff875c
4
71
2022-11-16 00:49:48
c5a20e82bd20a0792c1a93825fae4a99b98f33cfce57aec5f319f1a157ed4556
1
72
2022-11-15 10:09:02
d66a160c3db8aa5798f87e517a9ad79ef096e6bd16857995844d3dca452a3756
3
71
2022-11-14 17:07:36
88a6dcb03662d79db707db033ced58ebde7fc3ebc42019cfa4f9c80181180451
3
68
2022-11-14 17:07:36
c50bfa00cb1ee16e98a2140f1e8e1ea26a494d31531f113ee822161f40389b51
1
66
2022-11-14 06:33:36
0e4710e864cfec2edb2d8e126b2c4addde86601882bdad650d83b03baf3a1fe5
2
72
2022-11-13 19:43:05
eae9c36ee953fbe84f938a361d1f14805a39d9bea84be9679e8831d4e4fdf93b
1
70
2022-11-12 18:00:39

Rule Matches per Month (last 24 months)