Files

2.6 KiB

1appnote
2remcom.exeESCU - This process is an open source replacement to psexec and is not typically seen in an enterprise environment.
3pwdump.exeESCU - This process is associated with a tool used to dump password hashes on a Windows system.
4pwdump2.exeESCU - This process is associated with a tool used to dump password hashes on a Windows system.
5nc.exeESCU - This process is an open source tool used for network communications.
6wce.exeESCU - This process is associated with a tool used to dump hashes and execute pass-the-hash and pass-the-ticket attacks.
7cain.exeESCU - This process is associated with a tool used to collect user credentials and execute attacks.
8nmap.exeESCU - This process is an open source network mapping tool used to identify hosts and listening services on a network.
9kidlogger.exeESCU - This process is associated with a tool used to collect keyboard input on a host.
10isass.exeESCU - This process name is used by attackers to hide in plain sight and look like a legitimate Windows system process.
11svch0st.exeESCU - This process name is used by attackers to hide in plain sight and look like a legitimate Windows system process.
12at.exeESCU - This process is used to schedule other processes to run. schtasks.exe should be used instead as it provides more flexibility.
13getmail.exeESCU - This process is seen to be used by attackers to extract email files from host machines.
14ntdll.exeESCU - This process was identified as malicious by DHS Alert TA18-074A.
15netpass.exeESCU - This process was identified as malicious by DHS Alert TA18-201A and attackers use this tool to recover all network passwords stored on your system for the current logged-on user.
16WebBrowserPassView.exeESCU - This process was identified as malicious by DHS Alert TA18-201A and is used by attackers as a password recovery tool that reveals the passwords stored in Web Browsers.
17OutlookAddressBookView.exeESCU - This process was identified as malicious by DHS Alert TA18-201A and is used by attackers to steal the details of all recipients stored in the address books of Microsoft Outlook.
18mailpv.exeESCU - This process was identified by DHS Alert TA18-201A and attackers use this tool is a password-recovery tool that reveals the passwords and other account details from various email clients.
19NLBrute.exeESCU - This process was identified in the SamSam Ransomware Campaign and attackers use this tool to brute force RDP instances with a range of commonly used passwords.
20selfdel.exeESCU - This executable was delivered in the SamSam Ransomware Campain and the attackers levereged this binary to delete its malicilous activities.