Windows Process Execution of PCHunter (PCHunter64.exe or PCHunter32.exe)

Flags Windows execution of PCHunter64/32.exe using image path plus PE metadata and known hashes.

FreeReviewedSigma · High · v2
Product
windows
Category
process_creation
Author
Florian Roth (Nextron Systems), Nasreddine Bencherchali (SigmaHQ), DRL 1.1
Published
2022-10-10
Updated
2026-07-31
title: Windows Process Execution of PCHunter (PCHunter64.exe or PCHunter32.exe)
id: 34fff399-15c1-4907-ad95-0f549d74e841
status: test
description: This rule flags execution of the PCHunter utility on Windows by matching the process image name ending with PCHunter64.exe or PCHunter32.exe, along with specific file metadata (OriginalFileName and description) and known hashes. Attackers may use PCHunter-like tooling to inspect and manipulate process and kernel-related behavior as part of discovery or system interaction. The detection relies on process creation telemetry including the executable path, file properties, and hash values.
references:
  - https://web.archive.org/web/20231210115125/http://www.xuetr.com/
  - https://www.crowdstrike.com/blog/falcon-overwatch-report-finds-increase-in-ecrime/
  - https://www.hexacorn.com/blog/2018/04/20/kernel-hacking-tool-you-might-have-never-heard-of-xuetr-pchunter/
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_hktl_pchunter.yml
author: Florian Roth (Nextron Systems), Nasreddine Bencherchali, Huntrule Team
date: 2022-10-10
modified: 2024-11-23
tags:
  - attack.execution
  - attack.discovery
  - attack.t1082
  - attack.t1057
  - attack.t1012
  - attack.t1083
  - attack.t1007
logsource:
  category: process_creation
  product: windows
detection:
  selection_image:
    Image|endswith:
      - \PCHunter64.exe
      - \PCHunter32.exe
  selection_pe:
    - OriginalFileName: PCHunter.exe
    - Description: Epoolsoft Windows Information View Tools
  selection_hashes:
    Hashes|contains:
      - SHA1=5F1CBC3D99558307BC1250D084FA968521482025
      - MD5=987B65CD9B9F4E9A1AFD8F8B48CF64A7
      - SHA256=2B214BDDAAB130C274DE6204AF6DBA5AEEC7433DA99AA950022FA306421A6D32
      - IMPHASH=444D210CEA1FF8112F256A4997EED7FF
      - SHA1=3FB89787CB97D902780DA080545584D97FB1C2EB
      - MD5=228DD0C2E6287547E26FFBD973A40F14
      - SHA256=55F041BF4E78E9BFA6D4EE68BE40E496CE3A1353E1CA4306598589E19802522C
      - IMPHASH=0479F44DF47CFA2EF1CCC4416A538663
  condition: 1 of selection_*
falsepositives:
  - Unlikely
level: high
license: DRL-1.1
related:
  - id: fca949cc-79ca-446e-8064-01aa7e52ece5
    type: derived