Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
38 distinct techniques documented for this family, organized by ATT&CK tactic.
T1112 Modify Registry Adversaries may interact with the Windows Registry ...
T1543 Create or Modify System Process ... Adversaries may create or modify system-level processes to repeatedly execute malicious payloads as part of persistence.
"PCHunter64.exe" (Access type: "CREATE"; Path: "HKLM\SYSTEM\CONTROLSET001\SERVICES\PCHUNTER64") ... Key: "IMAGEPATH"; Value: "C:\PCHunter64.sys"
T1055.012 Process Hollowing ... Adversaries may inject malicious code into suspended and hollowed processes in order to evade process-based defenses.
T1055.013 Process Doppelg��nging ... Adversaries may inject malicious code into process via process doppelg��nging
Contains ability to enable or disable privileges in the specified access token (API string) details Observed api string:"AdjustTokenPrivileges" ... ATT&CK ID T1134
T1134.001 Token Impersonation/Theft ... Adversaries may duplicate then impersonate another user's token ...
T1543 Create or Modify System Process ... Adversaries may create or modify system-level processes to repeatedly execute malicious payloads as part of persistence.
"PCHunter64.exe" (Access type: "CREATE"; Path: "HKLM\SYSTEM\CONTROLSET001\SERVICES\PCHUNTER64") ... Key: "IMAGEPATH"; Value: "C:\PCHunter64.sys"
T1547.006 Kernel Modules and Extensions ... Adversaries may modify the kernel to automatically execute programs on system boot.
Anti-Detection/Stealthyness PE file contains executable resources ... source Static Parser relevance 10/10 ATT&CK ID T1027
PE file has a section name known to be used by a packer/protector PE file is protected by VMProtect ... ATT&CK ID T1027.002
T1055.012 Process Hollowing ... Adversaries may inject malicious code into suspended and hollowed processes in order to evade process-based defenses.
T1055.013 Process Doppelg��nging ... Adversaries may inject malicious code into process via process doppelg��nging
"PCHunter64.exe" marked "C:\PCHunter64as.sys" for deletion ... ATT&CK ID T1070.004
Contains ability to enable or disable privileges in the specified access token (API string) details Observed api string:"AdjustTokenPrivileges" ... ATT&CK ID T1134
T1134.001 Token Impersonation/Theft ... Adversaries may duplicate then impersonate another user's token ...
T1497 Virtualization/Sandbox Evasion ... Possibly tries to implement anti-virtualization techniques ... The input sample contains a known anti-VM trick
T1010 Application Window Discovery Adversaries may attempt to get a listing of open application windows.
Queries sensitive IE security settings ... Queries the internet cache settings ... ATT&CK ID T1012
T1016 System Network Configuration Discovery ... Adversaries may look for details about the network configuration and settings
T1057 Process Discovery Adversaries may attempt to get information about running processes on a system.
T1082 System Information Discovery ... get detailed information about the operating system and hardware
Discovery T1083 File and Directory Discovery ... Adversaries may enumerate files and directories
Observed import api "NetUserEnum" which can "Retrieves information about all user accounts on a server." ... ATT&CK ID T1087.001
T1497 Virtualization/Sandbox Evasion ... Possibly tries to implement anti-virtualization techniques ... The input sample contains a known anti-VM trick
T1518.001 Security Software Discovery ... References security related windows services
Credential Access T1056.001 Keylogging ... Adversaries may log user keystrokes to intercept credentials
Installs hooks/patches the running process ... wrote bytes ... part of module "WININET.DLL" ... ATT&CK ID T1056.004
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.