Rule Info
Name
Winnti_APT_Hdump_Tool
Author
Florian Roth
Description
Password dumper used by Winnti group - file pn.exe
Score
105
Reference
Internal Research
Date
2016-09-30
Minimum Yara
1.7
Rule Hash
bc0c5568d601860803b1c6de7ff561d7
Tags
['APT', 'FILE', 'T1003', 'G0044', 'EXE', 'CHINA']
Required Modules
[]
Virustotal Matches
Antivirus Verdicts
Rating
Number of Samples
Malicious (>= 10 engines)
4
Suspicious (< 10 engines)
3
Clean (0 engines)
0
Rule Matches
Timestamp
Positives
Total
Hash
VT