Files

5.3 KiB

1attacker_tool_namesdescription
2advanced_port_scanner.exeAdvanced Port Scanner is a free network scanner allowing you to quickly find open ports on network computers and retrieve versions of programs running on the detected ports.
3cain.exeThis process is associated with a tool used to collect user credentials and execute attacks.
4certify.exeA tool used to enumerate and abuse misconfigurations in Active Directory Certificate Services (AD CS)
5certipy.exeA tool used to enumerate and abuse misconfigurations in Active Directory Certificate Services (AD CS)
6FolderContentsDeleteToFolderDelete.exeThis process is associated with code for taking advantage of filesystem-based exploit primitives.
7FolderOrFileDeleteToSystem.exeThis process is associated with code for taking advantage of filesystem-based exploit primitives.
8fscan.exeFscan is a tool used to scan for open ports and services on a network.
9getmail.exeThis process is seen to be used by attackers to extract email files from host machines.
10hash32.exeThis process is used to dump password hashes on a Windows system.
11hash64.exeThis process is used to dump password hashes on a Windows system.
12htran.exeThis process is used to dump password hashes on a Windows system.
13isass.exeThis process name is used by attackers to hide in plain sight and look like a legitimate Windows system process.
14kidlogger.exeThis process is associated with a tool used to collect keyboard input on a host.
15KPortScan3.exeKPortScan 3.0 is a widely used port scanning tool on Hacking Forums to perform network scanning on the internal networks.
16mailpv.exeThis process was identified by DHS Alert TA18-201A and attackers use this tool is a password-recovery tool that reveals the passwords and other account details from various email clients.
17masscan.exeThis executable was delivered in the XMRig Crypto Miner
18Massscan_GUI.exeThis executable was delivered in the XMRig Crypto Miner
19mimikatz.exeMimikatz is an open-source application that allows users to view and save authentication credentials such as Kerberos tickets.
20mm32.exeThis is a process name was seen being used as a rename of mimikatz.exe.
21mm64.exeThis is a process name was seen being used as a rename of mimikatz.exe.
22nc.exeThis process is an open source tool used for network communications.
23netpass.exeThis process was identified as malicious by DHS Alert TA18-201A and attackers use this tool to recover all network passwords stored on your system for the current logged-on user.
24NLAChecker.exeA scanner tool that checks for Windows hosts for Network Level Authentication. This tool allows attackers to detect Windows Servers with RDP without NLA enabled which facilitates the use of brute force non microsoft rdp tools or exploits
25NLBrute.exeA RDP brute force tool found in botnets for further expansion and and acquisition of targets. This process was identified in the SamSam Ransomware Campaign and attackers use this tool to brute force RDP instances with a range of commonly used passwords.
26nmap.exeThis process is an open source network mapping tool used to identify hosts and listening services on a network.
27ns.exeA commonly used tool used by attackers to scan and map file shares
28ntdll.exeThis process was identified as malicious by DHS Alert TA18-074A.
29OutlookAddressBookView.exeThis process was identified as malicious by DHS Alert TA18-201A and is used by attackers to steal the details of all recipients stored in the address books of Microsoft Outlook.
30pwdump.exeThis process is associated with a tool used to dump password hashes on a Windows system.
31pwdump2.exeThis process is associated with a tool used to dump password hashes on a Windows system.
32quarkpwdMtCrt.exeThis process is associated with a tool used to dump password hashes on a Windows system.
33remcom.exeThis process is an open source replacement to psexec and is not typically seen in an enterprise environment.
34seatbelt.exeA tool used to collect detailed information about a system—such as remote access configurations network shares and other security-relevant data on victim machine.
35selfdel.exeThis executable was delivered in the SamSam Ransomware Campaign and the attackers leveraged this binary to delete its malicious activities.
36SharpGPOAbuse.exeSharpGPOAbuse is a tool that allows you to abuse and enumerate GPOs on a Windows system.
37SharpHide.exeSharpHide is a tool that allows you to hide a process from the task manager.
38SharpStay.exeSharpStay is a tool that allows you to stay hidden from the task manager.
39sharpTask.exeSharpTask is a tool that allows you to create scheduled tasks on a Windows system.
40SilverBullet.exeMalware was discovered in our monitoring of honey pots that abuses this open source software for scanning and connecting to hosts.
41svch0st.exeThis process name is used by attackers to hide in plain sight and look like a legitimate Windows system process.
42wce.exeThis process is associated with a tool used to dump hashes and execute pass-the-hash and pass-the-ticket attacks.
43wce32.exeThis process is associated with a tool used to dump hashes and execute pass-the-hash and pass-the-ticket attacks.
44wce64.exeThis process is associated with a tool used to dump hashes and execute pass-the-hash and pass-the-ticket attacks.
45WebBrowserPassView.exeThis process was identified as malicious by DHS Alert TA18-201A and is used by attackers as a password recovery tool that reveals the passwords stored in Web Browsers.