T1003.001 LSASS Memory in real malware
ATT&CK technique T1003.001 LSASS Memory appears in 60 publicly analyzed samples on MalwareAnalyzer by Cyble, 0.1% of the analyzed corpus. Seven-day prevalence is flat (0 recent vs 0 prior). Most associated families: Fugrafa, Brontok, Mimikatz, Small.
Tactics: credential-access
Prevalence in the corpus
- Samples exhibiting T1003.001: 60
- Share of analyzed corpus: 0.1%
- Last 7 days: 0 · prior 7 days: 0 (flat)
Malware families using T1003.001
Example samples
- cbe7e7925d3dddb228f61f1ebe6a9008cd14eb403a718330218d72dbfabb36e0 - malicious
- 10cf4247d00a3d445328cbdede08796e5a7c3a42d27e9a7d3e562a68960ca1c0 - malicious
- eac27a3ad2b12f01a89ba32fa29bd9cbfa3b2ec460b0f1db1ebd368281ed6b4a - malicious
- c52083290a6fcd1f24ec25070ee7fccbd46188f06c09f34ca1f76789f1b98497 - malicious
- 808eadb019009e993307e8db249bc0c77850fdf96874819d389d0aa31482f88e - malicious
- 03216d525ba58e647dfbb00c0ae8528af967047a3783d57975d77682cdfafab6 - malicious
- adccb0aae52643f57cbe06172040ca32870dc499e0a1a842ee4480f0870b033c - malicious
- fb139cf254a9e87e63ae25084c5a105c1a0e94db93225fa76adebf4ac27c98ea - malicious
- ce3ae542f3bd14af77a37565df528fba52b73676f20a4d318b148533418e65c9 - malicious
- a130eb3e26dcf721f1e9330880b2d15999298d1ee24b48cf61b048cfb2c84bc8 - malicious
- ab3149341303b58cc6f3fd71b101186f4f6796582a15dd57db0d09c943988168 - malicious
- 7ed18001ffca3f4ce4d2eaee6410d1602837b436c3a16688448d380745288ba1 - malicious
- 5a6e990d67cb032ab706e8db07fbe0f991d81c1daec6d4e858620276676d963d - malicious
- e28da9ff108ef0fe1043a267d4eab5cb5a8c5e378067fa86fc3c3094320aba3f - malicious
- db79ee24eba89e92e85d48d397b219af73aea31e6451724a8975106ff84f00b4 - malicious
- 83358f4c1bae1867fd7f19f4fe25f035f2c49e45c2092c181ba8d7370724d6b2 - malicious
- 22fc1c55fb5d5db2ac09a63718f2c89685e04434df9067c06f4e0c2b174cf687 - malicious
- 4a5463b4e5a0907d721e9844a1204188fd0b85b6e0e2c6d428efc39a65389008 - malicious
- f82f6b23eee3b5ec2784b4510e1e716ab83228416741323823dae03c3f6bf893 - malicious
- f88161aab5bb74fdbf7c35d0be24b3187a82cde25ce4f818651fb8e3bf25c892 - malicious
- aeb5317d9ecfd982c0615147942a5f433b83f60ed5307aebf4e7b1bbad5fa464 - malicious
- 95e3b475d5943959da86c9e56016794a21bc531be140a654bd5683070344c551 - malicious
- d7cb2448c50b3f2f97efc0748b904e047be9a3bea5bcb9941fc4853ed26c4c65 - malicious
- 381e093efa9bd0b165894b03e92c57fa6d531b4268448122b5ae76c3513175ea - malicious
- 451aecde7836384a42920c1e3cd4bfe1bf49c4cba1d0fda65919e9f2c78f41de - malicious
Canonical technique definition: MITRE ATT&CK T1003.001 (ATT&CK v19.1, CC BY 4.0).
Frequently asked about T1003.001
- How common is ATT&CK T1003.001 (LSASS Memory) in real malware?
- ATT&CK technique T1003.001 LSASS Memory appears in 60 publicly analyzed samples on MalwareAnalyzer by Cyble, 0.1% of the analyzed corpus. Seven-day prevalence is flat (0 recent vs 0 prior). Most associated families: Fugrafa, Brontok, Mimikatz, Small.
- Which malware families use T1003.001?
- In this corpus T1003.001 is most associated with Fugrafa (56), Brontok (1), Mimikatz (1), Small (1). Counts are analyzed samples per family in which the technique was observed.
- What share of analyzed samples use T1003.001?
- 0.1% of the publicly analyzed corpus (60 of 114611 samples) exhibits T1003.001. Technique attribution comes from behavior captured during real sandbox detonation and from static analysis, not from a vendor label.
All ATT&CK techniques in the corpus · Latest analyzed threats