SynRpcServer.exe in System32 folder

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

SynRpcServer.exe in System32 folder

L1 Bithead

Hi,

I got an alert "Globally rare process execution from a signed process" and after investigating the process is SynRpcServer.exe

which not uncommon and also the host uses a fingerprint sensor so it should all make sense.

But the interesting parts are on the causality chain are:

  • SynRpcServer.exe executed "SynRpcServer.exe".
  • The acting process is signed by Synaptics Incorporated.
  • This signed vendor, image name and executed process combination is globally uncommon.
Furthermore the location of the exe is in System32 folder:
C:\Windows\System32\SynRpcServer.exe

Hash (of the parent SynRpcServer.exe) 10a416072f3e581e2943f07453c5484e503c47131e48674245564030de2dd531


Any thoughts on this?
2 REPLIES 2

L5 Sessionator

Hi @Panagiss, thanks for reaching us using the Live Community.

 

What module is generating the alert? BTP? Analytics?

Maybe the fingerprint driver/app has been updated and it is behaving different as before.

JM

It was from: XDR Analytics BIOC

  • 220 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!