SUSP_LSASS_Dumper_SilentProcessExit_Characteristics_Jun22_1

Rule Info

Minimum Yara
1.7
Tags
['T1183', 'T1086', 'SUSP', 'HKTL']
Name
SUSP_LSASS_Dumper_SilentProcessExit_Characteristics_Jun22_1
Description
Detects tool that dumps the LSASS process memory using WerFault
Rule Hash
0e69ca4a573a9a54b56bd8a3623ace74
Score
75
Required Modules
[]
Author
Florian Roth
Date
2022-06-27
Av Ratio
16.34

Antivirus Verdicts

Rating
Number of Samples
Malicious (>= 10 engines)
27
Suspicious (< 10 engines)
41
Clean (0 engines)
11

Rule Matches

Timestamp
Positives
Total
Hash
VT
2022-09-28 17:35:59
3
71
e60b946f4e7914466637f315a659a7e586a2f6228f0de9e9d966e47bc90bcf6d
2022-09-27 08:59:08
2
60
20d8c7bd7e34d152c3b9da8fe74bffc9fe4152ac3d53d07e6e559d56034574c7
2022-09-22 23:40:17
17
71
0908cea6319a6fe5690b5a43dde086cdd3747c836637ea7420f3605fc2ec8b40
2022-09-22 23:36:47
10
71
4c28d8e8b28441eb29e9779fca16e65e487fa420209138179c2c627fc278756c
2022-09-22 23:30:21
7
72
c0372402023bbcebc5eb9c258c87adfafa3a1f41c2a4151da02868e7d3464628
2022-09-22 13:02:01
1
70
bf809991db961e9a6f47e75a4b994ee21989e6ac940eaf482a3cf5c0165132b4
2022-09-21 23:12:52
30
71
be622fa57ad77310cb4c9ed8fa8a2a9f0db06f3f07e02e6b95e83af7b4b05a40
2022-09-21 09:07:30
0
69
6d5299786e286f835724fb19ca7aa91d1231047a9ea0d6b91b393a845c492503
2022-09-20 11:56:27
1
69
b7bcb3ea282dfabe79629d591174b871c50e467dee189fa66ffed3f11004740e
2022-09-20 05:08:31
0
69
7c3e49e9a551f33ae11b446a9994db5d63cb9dccbb30e427da91d439f25a0486
2022-09-19 17:13:13
6
70
1b0d1fd6876a0e0bb95299f7e781d80f35ab2caf0097b6816a7c169b53cb0192
2022-09-14 05:07:25
22
71
b9f6519d2add618b62befda29a15b5c2c73a785838b937c7cce9698488020723
2022-09-13 01:38:49
47
71
ec9fbc7d00ce385098d6f23026ae64c25ddb63a3c14980b428a818d6fb477c6d
2022-09-12 15:00:42
23
71
b77399f19e33191bfcb3f3ed63122b730dbc7eb73eecc8fafc8f2023fde0742f
2022-09-12 14:55:19
22
71
96890f2b48ed2b79b57c0955033440fd21f0e3eb15fd245da8c7d08f091af090
2022-09-11 16:10:10
31
71
5aaff354c73e03f770f47642d405fb45380c59bd46030313ac03cbf2a706d5e5
2022-09-07 21:38:21
51
71
0bb0388d81111aff26bc79a952abf0435d0c909dad4a8f62136fed3b5c8d7098
2022-09-01 14:12:41
18
70
abd7624fad15be9fec1e194b611630bc7763c0560a74b5be7004aa9fc4491c1e
2022-08-31 11:06:59
0
58
3bc48434ab9b4a4ecb908bf4e03f77b6c3b6a8731fc040685bd2b5f236c23c49
2022-08-26 13:47:45
3
70
dabeab5243d6d8f0dcc1ccf2ace33d7c6c3a1cb681bebbca53c8611cc0b83ad1
2022-08-25 14:36:34
22
70
8fff06805609947dd608c8e11a2a9349024a1d0c834799e4d18206a548b7d468
2022-08-21 04:15:31
0
69
90aa0ccbea1e193423945498388f1653a53c88c5160ef64e9559a172b9a76382
2022-08-19 23:53:46
8
71
0c31114b80ddddac6e1d067c73dd8d8c46ded313eb329279c751d09ddaa6614e
2022-08-19 23:47:14
6
70
7ab722bcacba3d3e45beb740b3753b335bdae8b1e73091564bd0cc9cd8cae1c6
2022-08-19 23:40:24
6
68
ecfe713e1af9d4c4f0a8ba9edf8d7d885d92566002e5a17d2b10df487c8933a6
2022-08-19 21:24:48
5
69
454c069e914303de3fe9c07847e0f9775f1f0d1724e75b0f92709a41d750268f
2022-08-19 21:11:54
3
70
cd8afbf3fcd90314894f7414edd30bc6e0a71fee1c4c4aa7cf8443b1b4272315
2022-08-19 21:10:14
5
70
433cef7c84f11f155362dca45991ef80ad23fe0f5ee16cd1b9db90bf386f7c6e
2022-08-19 20:35:11
5
70
0924a95e3925aa0bd5d33dfd0890f4d4ba0b9b765fa98cbbe9992f2f2c5aece5
2022-08-19 20:27:40
5
70
23988ccb37fd54e11406741bb8f93bfc8074ae3205311b05da8c7e60093b24ec
2022-08-19 20:17:51
5
70
c4937653573c96de90a146b89a2c97f3a22f5ecdffdbdcff6c6f9fbcfd774b2e
2022-08-19 19:47:09
4
69
8869a6863b95140839027927fb474425a7fdd29e4357b1d2ef301ec139f1390d
2022-08-19 19:38:15
4
70
01dacf922c7510b81ab2670da0e5d7d83952fbb55ae2fcc2c4c6937fa882ba49
2022-08-19 19:23:31
5
70
ddb30e65ce19d5bce5938f637de76b01262472a542bf71b2873bbb01cc660d5c
2022-08-19 12:49:52
4
70
532d4a63d87d30eea3a44f83b6ebf60fc3f193d849f8a543103b4faea2a16e79
2022-08-19 12:39:41
4
70
6456f89211ffaf9d65b87a6534b220ed95e5346d95dce55e9c078d1ef5158a00
2022-08-19 12:21:44
5
70
ad0ab1b2e4e6786a657f514d765862209150758c5c306f959f5d22a9944c1ee0
2022-08-19 12:06:48
4
70
b5be790f03cd2a8d3fcb08ba61805cb0221873be890901df0af6fbd7bf67a236
2022-08-19 12:03:35
6
70
6f21d47289962e6f2c8be40f7b86d4c4313b43fc2472a9eb4b35f45e52099151
2022-08-18 18:03:47
6
70
db09fcded6d85f0e8503ca0016ba1f9e47e332c366f03377c77bbd5a0e2ecd11
2022-08-18 17:40:14
4
70
0b53516192625b96ff6f550d409da1adb77342c3a75fb437bada72b708f62f97
2022-08-18 17:05:35
4
70
337de0c7df6b105b44609932130633692b9b1b29c1d1e6e3352952f54dd0b90b
2022-08-18 16:51:52
5
70
331076558ffde8d1200f58495c35e9d8a70ce372a5fa700125d80b96abf56553
2022-08-18 13:21:12
5
70
6c900162f0a2b44388d3ca49cbe0542c6acc56c0a27d05e2b25a2a05f6a6a70d
2022-08-17 20:16:17
0
69
c6273525fe7a3a791463859dff25a5fa27c3b8cdd16ca68cfb6f8abb4b8930f8
2022-08-15 15:22:13
1
70
0723a1bea20ae0b94292989fa62f15acb9fedf5297375ef87ede0fd3acb0ade4
2022-08-14 03:00:35
18
71
863e6bc947bb73fba146862d5aa53fc3199a4dd318a1e681ad697ed6d98bd203
2022-08-14 03:00:35
3
70
37b7a2f77c0da070102f8ef1c9d908b9d8f01f56048f181f86fd0ae4d1175552
2022-08-10 01:24:52
50
71
20b650bd00cae666a85d07ae38502a7545b6ba913183362cf3f8b810da22ff3c
2022-08-08 20:40:38
6
70
897f4fd8dd12083e4cc121b435ec74b129cd36a309fba22ad148e98752ba013e
2022-08-03 23:29:24
41
71
2d3427d91da0275904aa0c9fe55fda831f7963a94020e243a72c46116729e7ec
2022-07-31 19:19:05
45
71
740dffff27e54095e7bac7c25910e110f2fbe15db17455e6454f48f9476ea8e2
2022-07-31 02:58:17
3
70
40a8c76e7498f1e2296b9ed77c519a8fe93d8f891f4f33b25d3a720548f1428c
2022-07-29 16:38:26
11
71
e4a2ab49ce4925caec4447221bc7352a05fce1098522b60b87c728b72eac12d2
2022-07-29 02:09:39
25
68
bd88de1dea6fbc166d62841338e6d59ab08facfbea1219616888f16b01cc163c
2022-07-28 08:43:25
5
69
0210a6fddad8dab42f62302e4b136c7beb9f97eeffe186d1eb20aa2648c9b33f
2022-07-27 22:32:52
16
69
6b835ebcb6730c66cf50d1634f59c0f4cf7a62ca991d48e7bddfb724efb3587a
2022-07-23 08:41:33
9
70
f04270ab2b7da01b1d5067a170b20f81edf010c91ad6959e4767adfb35e8dccc
2022-07-23 08:07:18
0
69
b57affb6c68b43b8dc3015c06d066ae61957cecd324ecece8c4c332b82492724
2022-07-22 08:58:32
0
68
df69c78f5115df22654fd3bc655a13c32c262d15e6e5e41e17c8d1b363de3a58
2022-07-19 15:27:06
24
70
a459566b347cde6a8b646f2047d89eb313372ab95f456faae181e1919cc0cfde
2022-07-18 18:02:35
0
58
b20561616dd8530dea43495b60fa9ba000a45832eb4b24289c7aa45bf2e6cd00
2022-07-14 21:20:20
3
57
51135b0a96327b1c85358926e34f0abf65111eee24fca15fd46e80a76c8c4d3a
2022-07-13 05:36:14
3
69
a31e664e79a6252591d6c3edf9aa68bf11bf9efe7b6c5875846727f6165b4b6b
2022-07-12 08:44:00
42
64
1a1cee5613c5126cfc0af51e72559b7f77560c7d7664936753622a0d9b836192
2022-07-12 08:07:28
0
68
abeb0074e77dfe91b5b9ef243eb5ddc17aba729ba6038e64b0cf4b45f8729c4e
2022-07-11 18:26:07
15
67
551ce2655fa716da75a98eaa75a7fd8f460aa944578775f91498de3ecb32e740
2022-07-11 18:26:06
13
68
740af3b237707b338f6a209ac86f5fafec55ea5aa61b8447741f3dfadcf1302b
2022-07-10 18:11:51
2
68
6c3d3296b13b971729a6ae9296f5657e05d229748374a29ca2e38e1d3d1570b3
2022-07-10 17:36:54
14
68
23bfd2022e16feab0df970005a72357a232f7e878db834ca820fc8726e23fcc5
2022-07-10 07:59:00
45
69
b9ab3277ab6be3ba6da764e7ee6916e274d635ff875b9f0b795807ca575f7f58
2022-07-10 05:27:36
0
67
3b1a3398ac7a100ecfbfaa473046c6b7f5522537d536bf945fa795c357921e6e
2022-07-05 20:00:08
0
66
35f0398dd6d5e5d4156e82893a2d17076d91e2a1087114ade20f79b8ce34037f
2022-07-05 11:54:16
1
62
910f848d7dce3eb2ee2316bc1c2234956d661efdd80df93d117680644c1eefc6
2022-07-05 11:54:16
12
66
c29f1b08a0d18c0dc86ec86cc12d737a8d96a205c4a5ba33ef48ff77548c888e
2022-07-05 11:40:50
4
67
87998b8b30ee073b12f439408a5c79650869677d45b9e5bae11fed754668e1c9
2022-07-04 16:12:01
35
69
f1c9a8ebd23f23ad291978f20b729973f9f86e65d9e9d5c73913b4a64518ec13
2022-07-04 08:02:32
7
67
faf93b856f6128730a84855688f0842cfaf6ea82ebf8da1335ac36113e4a097b
2022-07-02 08:10:51
22
69
88559ac8dc69440d73f380f555ec9cb6210aa1e21dd8f1ae95bb675ab289e0bb

Rule Matches per Month (last 24 months)