Windows renamed dctask64.exe execution via known IMPHASH values

Flags Windows process creations where a renamed dctask64.exe execution matches known IMPHASH values.

FreeReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2020-01-28
Updated
2026-07-30

ATT&CK techniques

Priv Esc → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule identifies process executions where the binary hash matches one of several known IMPHASH values associated with a renamed dctask64.exe (ZOHO ManageEngine Endpoint Central) execution. Renaming trusted system or vendor binaries can help attackers evade name-based detection and blend into legitimate activity. It relies on Windows process creation telemetry containing the process image path/name and the IMPHASH field to match these specific indicators while excluding cases with a matching legitimate name pattern.

Related detections9 linkedT1218 — drag to rearrange
Windows ConHost Spawning Suspicious Script and Command-Line Child Processes
Suspicious Child Process Creation from BgInfo.EXE on Windows
Windows: Suspicious Child Process Spawned by VsCode code.exe
Windows WSL Process Spawning Uncommon Child Executables
Windows: Alert on Unusual Child Process of Setres.EXE Spawning 'choice' Executables
Windows msdt.exe Execution with Suspicious Parent Process
Windows sdiagnhost.exe Spawns Suspicious Child Process (PowerShell/CMD/MSHTA/etc.)
Windows Process Creation: Detect Sysinternals Tool Name Impersonation by Executable
Windows ZipExec-Style Suspicious PowerShell/Command Execution with Password-Protected ZIP
Windows renamed dctask64.exe execution via known IMPHASH values
Pivot detection · T1218 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.