Files
splunk-security_content/lookups/csv/windows_suspicious_tasks.csv

26 KiB

1task_nametask_commandtask_argumentstooltool_categorytool_typelinkseveritycommentreference
2*powershell.exe*shell command useexploitationgreyware_toolhttps://attack.mitre.org/techniques/T1053/005/mediumN/A
3*wscript.exe*shell command useexploitationgreyware_toolhttps://attack.mitre.org/techniques/T1053/005/mediumN/A
4*cscript.exe*shell command useexploitationgreyware_toolhttps://attack.mitre.org/techniques/T1053/005/mediumN/A
5*cmd.exe*shell command useexploitationgreyware_toolhttps://attack.mitre.org/techniques/T1053/005/mediumN/A
6*sh.exe*shell command useexploitationgreyware_toolhttps://attack.mitre.org/techniques/T1053/005/mediumN/A
7*ksh.exe*shell command useexploitationgreyware_toolhttps://attack.mitre.org/techniques/T1053/005/mediumN/A
8*zsh.exe*shell command useexploitationgreyware_toolhttps://attack.mitre.org/techniques/T1053/005/mediumN/A
9*bash.exe*shell command useexploitationgreyware_toolhttps://attack.mitre.org/techniques/T1053/005/mediumN/A
10*scrcons.exe*shell command useexploitationgreyware_toolhttps://attack.mitre.org/techniques/T1053/005/mediumN/A
11*pwsh.exe*shell command useexploitationgreyware_toolhttps://attack.mitre.org/techniques/T1053/005/mediumN/A
12powershell.exe*-Command whoami*whoamiDiscoverygreyware_toolhttps://github.com/mthcht/awesome-listsmediumN/Ahttps://github.com/mthcht/awesome-lists
13powershell.exe-encodedCommand *powershellDefense Evasiongreyware_toolhttps://github.com/mthcht/awesome-listsmediumbase64 encoded command from a scheduled taskhttps://github.com/mthcht/awesome-lists
14powershell.exe-enc *powershellDefense Evasiongreyware_toolhttps://github.com/mthcht/awesome-listsmediumbase64 encoded command from a scheduled taskhttps://github.com/mthcht/awesome-lists
15cmd.exe*/c whoami*whoamiDiscoverygreyware_toolhttps://github.com/mthcht/awesome-listsmediumN/Ahttps://github.com/mthcht/awesome-lists
16\area41C:\_Microsoft\Microsoft.exeCryptInjectMalwareoffensive_toolhttps://github.com/roadwy/DefenderYara/blob/9bbdb7f9fd3513ce30aa69cd1d88830e3cf596ca/Trojan/Win32/CryptInject/Trojan_Win32_CryptInject_PJ_MTB.yar#L36criticalN/Ahttps://github.com/mthcht/awesome-lists
17\OfficeServicesStatus*wscript*\public\*ISMDoorMalwareoffensive_toolhttps://unit42.paloaltonetworks.com/unit42-oilrig-uses-ismdoor-variant-possibly-linked-greenbug-threat-group/highN/Ahttps://github.com/mthcht/awesome-lists
18\Business Aviation*wscript*GootloaderMalwareoffensive_toolhttps://news.sophos.com/en-us/2024/11/06/bengal-cat-lovers-in-australia-get-psspsspssd-in-google-driven-gootloader-campaign/criticalN/Ahttps://github.com/mthcht/awesome-lists
19\Destination Branding*wscript*GootloaderMalwareoffensive_toolhttps://news.sophos.com/en-us/2024/11/06/bengal-cat-lovers-in-australia-get-psspsspssd-in-google-driven-gootloader-campaign/criticalN/Ahttps://github.com/mthcht/awesome-lists
20\InetlSecurityAssistManager*wscript *OopsIEMalwareoffensive_toolhttps://unit42.paloaltonetworks.com/unit42-oopsie-oilrig-uses-threedollars-deliver-new-trojan/highN/Ahttps://github.com/mthcht/awesome-lists
21*wevtutil.execl *wevtutilDefense Evasiongreyware_toolhttps://github.com/mthcht/awesome-listshighclearing event logs with wevtutil.exehttps://github.com/mthcht/awesome-lists
22\GoogleUpdateTaskMachineUI*update.vbs*HelminthMalwareoffensive_toolhttps://unit42.paloaltonetworks.com/the-oilrig-campaign-attacks-on-saudi-arabian-organizations-deliver-helminth-backdoor/highN/Ahttps://github.com/mthcht/awesome-lists
23\Wow64 Subsystem*programdata*mswow86.exe*NetSupport ManagerRAToffensive_toolhttps://thedfirreport.com/2023/10/30/netsupport-intrusion-results-in-domain-compromise/mediumN/Ahttps://github.com/mthcht/awesome-lists
24\copy*powershell.exe**Copy-Item*\ProgramData\*BlackJackRansomwareoffensive_toolhttps://github.com/mthcht/ThreatIntel-Reports/blob/3a4f91c1dbdc45f837f74ca4f3265caba6a09f84/Intel%20Reports/securelist_com/blackjack-hacktivists-connection-with-twelve_113959/content.txt#L1515highN/Ahttps://github.com/mthcht/awesome-lists
25\def*powershell.exe**Get-MpPreference*BlackJackRansomwareoffensive_toolhttps://github.com/mthcht/ThreatIntel-Reports/blob/3a4f91c1dbdc45f837f74ca4f3265caba6a09f84/Intel%20Reports/securelist_com/blackjack-hacktivists-connection-with-twelve_113959/content.txt#L1515highN/Ahttps://github.com/mthcht/awesome-lists
26\FJ_load*madHcCtrl.exe*DanabotInfostealeroffensive_toolhttps://securelist.com/tusk-infostealers-campaign/113367/highN/Ahttps://github.com/mthcht/awesome-lists
27\shell*Invoke-PowerShellTcpRun*Schtasks_latmov.batLateral Movementoffensive_toolhttps://github.com/S3cur3Th1sSh1t/Creds/blob/f71e780c51fdc2fdabe4e51831fa6289b1bede96/batch/Schtasks_latmov.bat#L2criticalN/Ahttps://github.com/mthcht/awesome-lists
28*StageProxyOps**HTTP-Server.ps1*HTTP-ServerPersistenceoffensive_toolhttps://github.com/NullArray/WinBins-Plus/blob/1e4af04ceaa8085b532757a1331113e919a20f4b/Scripts/persist.cmd#L2criticalN/Ahttps://github.com/mthcht/awesome-lists
29\GoogleUpdatesTaskMachineUI*fireeye.vbs*HelminthMalwareoffensive_toolhttps://unit42.paloaltonetworks.com/unit42-oilrig-actors-provide-glimpse-development-testing-efforts/highN/Ahttps://github.com/mthcht/awesome-lists
30\MicrosoftEdgeUpdateTaskMachineMS*EdgeBrowser.cmd*MeshAgentRAToffensive_toolhttps://github.com/mthcht/ThreatIntel-Reports/blob/3a4f91c1dbdc45f837f74ca4f3265caba6a09f84/Intel%20Reports/securelist_com/awaken-likho-apt-new-implant-campaign_114101/content.txt#L831highN/Ahttps://github.com/mthcht/awesome-lists
31\run1*cmd.exe**/c *\ProgramData\*BlackJackRansomwareoffensive_toolhttps://github.com/mthcht/ThreatIntel-Reports/blob/3a4f91c1dbdc45f837f74ca4f3265caba6a09f84/Intel%20Reports/securelist_com/blackjack-hacktivists-connection-with-twelve_113959/content.txt#L1515highN/Ahttps://github.com/mthcht/awesome-lists
32\SecurityAssist*Certutil*OopsIEMalwareoffensive_toolhttps://unit42.paloaltonetworks.com/unit42-oopsie-oilrig-uses-threedollars-deliver-new-trojan/highN/Ahttps://github.com/mthcht/awesome-lists
33\mstask*C:\temp\*Trojan.Win32.BreakWinMalwareoffensive_toolhttps://www.sentinelone.com/labs/meteorexpress-mysterious-wiper-paralyzes-iranian-trains-with-epic-troll/criticalN/Ahttps://github.com/mthcht/awesome-lists
34\ReportHealth*appdata*\srvHealth.exe*ISMInjectorMalwareoffensive_toolhttps://unit42.paloaltonetworks.com/unit42-oilrig-group-steps-attacks-new-delivery-documents-new-injector-trojan/highN/Ahttps://github.com/mthcht/awesome-lists
35*\Windows\Debug*suspicious pathsexploitationgreyware_toolhttps://github.com/mthcht/awesome-listsmediumtask in the *\Windows\Debug folderhttps://github.com/mthcht/awesome-lists
36\MicrosoftEdgeUpdateTaskMachineUC*\users\public\*autohotkeykeyloggeroffensive_toolhttps://thedfirreport.com/2023/02/06/collect-exfiltrate-sleep-repeat/highN/Ahttps://github.com/mthcht/awesome-lists
37*\Users\public*suspicious pathsexploitationgreyware_toolhttps://github.com/mthcht/awesome-listsmediumtask in the Public user profilehttps://github.com/mthcht/awesome-lists
38*\Users*\Downloads*suspicious pathsexploitationgreyware_toolhttps://github.com/mthcht/awesome-listsmediumtask in the users Downloads folderhttps://github.com/mthcht/awesome-lists
39*\Users*\Documents*suspicious pathsexploitationgreyware_toolhttps://github.com/mthcht/awesome-listsmediumtask in the users Documents folderhttps://github.com/mthcht/awesome-lists
40*\Users*\AppData\Roaming*suspicious pathsexploitationgreyware_toolhttps://github.com/mthcht/awesome-listsmediumtask in the roaming folderhttps://github.com/mthcht/awesome-lists
41*\Users*\AppData\Local*suspicious pathsexploitationgreyware_toolhttps://github.com/mthcht/awesome-listsmediumtask in the appdata folderhttps://github.com/mthcht/awesome-lists
42\SystemFailureReporter*\public\*SideTwist Backdoor (APT34)Malwareoffensive_toolhttps://research.checkpoint.com/2021/irans-apt34-returns-with-an-updated-arsenal/criticalN/Ahttps://github.com/mthcht/awesome-lists
43*\ProgramData*suspicious pathsexploitationgreyware_toolhttps://github.com/mthcht/awesome-listsmediumtask in the ProgramData folderhttps://github.com/mthcht/awesome-lists
44\MEGA\MEGAsync Update Task**\MEGAupdater.exeMEGASyncData Exfiltrationgreyware_toolhttps://mega.io/en/desktophighN/Ahttps://github.com/mthcht/ThreatHunting-Keywords/blob/main/tools/L-N/MEGAsync.csv
45\WallPaperChangeApp*\Autoit3\Autoit3.exe*OxtaRATMalwareoffensive_toolhttps://research.checkpoint.com/2023/operation-silent-watch-desktop-surveillance-in-azerbaijan-and-armenia/criticalN/Ahttps://github.com/mthcht/awesome-lists
46*\AppData\Local\Temp\*suspicious pathsexploitationgreyware_toolhttps://github.com/mthcht/awesome-listshightask in the temp folderhttps://github.com/mthcht/awesome-lists
47\Microsoft_Auto_Scheduler*\AppData\*Kube RansomwareRansomwareoffensive_toolhttps://x.com/ShanHolo/status/1880566701009563915/photo/1highN/Ahttps://github.com/mthcht/awesome-lists
48*:\Windows\Temp\*suspicious pathsexploitationgreyware_toolhttps://github.com/mthcht/awesome-listsmediumexecutable from the temp folderhttps://github.com/mthcht/awesome-lists
49*:\windows\system32\calc.exePOCexploitationgreyware_toolhttps://x.com/hackingforbeer/status/1719402854085951883mediumPOC schtasks /create /sc minute /tn 'dongs' /tr 'C:\windows\system32\calc.exe'https://github.com/mthcht/awesome-lists
50\tMicNet Work40,*.vbs*AsyncRATMalwareoffensive_toolhttps://any.run/cybersecurity-blog/asyncrat-open-directories-infection-analysis/criticalAsyncRAT’s Infection sampleshttps://github.com/mthcht/awesome-lists
51\yastcatWannamineCryptomineroffensive_toolcrowdstrike.com/blog/cryptomining-harmless-nuisance-disruptive-threat/criticalMoonero miner - command SCHTASKS /create /RU System /SC DAILY /TN yastcat /f /TR %temp%\y1.bat &&SCHTASKS /run /TN yastcathttps://github.com/mthcht/awesome-lists
52\OneNote 4726UnkownMalwareoffensive_toolhttps://x.com/Gi7w0rm/status/1864307803914981837mediumN/Ahttps://github.com/mthcht/awesome-lists
53\Microsoft\Windows\Power Efficiency Diagnostics\AnalyzeAllTrojan.Win32.BreakWinMalwareoffensive_toolhttps://www.sentinelone.com/labs/meteorexpress-mysterious-wiper-paralyzes-iranian-trains-with-epic-troll/criticalN/Ahttps://github.com/mthcht/awesome-lists
54\dongssuspicious namesexploitationoffensive_toolhttps://x.com/hackingforbeer/status/1719402854085951883mediumPOC schtasks /create /sc minute /tn 'dongs' /tr 'C:\windows\system32\calc.exe'https://github.com/mthcht/awesome-lists
55\StopVMMSandKillVMWPStopVMMSandKillVMWP scriptDefense evasionoffensive_toolhttps://x.com/GroupIB_DFIR/status/1750452267692728516highschtasks /create /tn StopVMMSandKillVMWP /tr 'powershell.exe -Command get-service -name vmms | stop-service -force ; taskkill /f /im vmwp.exe' /sc minute /mo 30 /ru SYSTEM /fhttps://github.com/mthcht/awesome-lists
56\SSH Key ExchangesshdPersistencegreyware_toolhttps://www.trellix.com/blogs/research/cactus-ransomware-new-strain-in-the-market/mediumcompliancehttps://github.com/mthcht/ThreatHunting-Keywords/blob/main/tools/R-T/schtasks.csv
57\SSH ServersshdPersistencegreyware_toolhttps://www.trellix.com/blogs/research/cactus-ransomware-new-strain-in-the-market/mediumcompliancehttps://github.com/mthcht/ThreatHunting-Keywords/blob/main/tools/R-T/schtasks.csv
58\MeterpeterC2redpillexploitationoffensive_toolhttps://github.com/r00t-3xp10it/redpill/blob/611d39b8bff717ac84d58550dc04e1b312acb19e/bin/SchTasks.ps1#L83criticalSchTasks.ps1https://github.com/mthcht/ThreatHunting-Keywords/blob/main/tools/R-T/redpill.csv
59\RedPillTaskredpillexploitationoffensive_toolhttps://github.com/r00t-3xp10it/redpill/blob/611d39b8bff717ac84d58550dc04e1b312acb19e/redpill.ps1#L743criticalredpill.ps1https://github.com/mthcht/ThreatHunting-Keywords/blob/main/tools/R-T/redpill.csv
60\SQLC2AgentPS*PowerUpSQLC2offensive_toolhttps://github.com/NetSPI/PowerUpSQL/blob/a83cad211983290bf38708e6e237cacbfe023e32/scripts/pending/SQLC2.ps1#L958criticalN/Ahttps://github.com/mthcht/awesome-lists
61My Startup TaskPowershell-Scripts-for-Hackers-and-PentestersPersistenceoffensive_toolhttps://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters/blob/788e89e9584b4b43f982721d59c06c77c0b3b566/PS-020.md?plain=1#L20mediumN/Ahttps://github.com/mthcht/awesome-lists
62*Set-MpPreference -DisableRealtimeMonitoring *powershellDefense Evasiongreyware_toolhttps://github.com/mthcht/awesome-listshighdisabling Defender Real time monitoringhttps://github.com/mthcht/awesome-lists
63\OneDrive SecurityNitrogenMalwareoffensive_toolhttps://news.sophos.com/en-us/2023/07/26/into-the-tank-with-nitrogen/highN/Ahttps://github.com/mthcht/awesome-lists
64\DemovaleNightdoorMalwareoffensive_toollhttps://github.com/mthcht/ThreatIntel-Reports/blob/3a4f91c1dbdc45f837f74ca4f3265caba6a09f84/Intel%20Reports/www_welivesecurity_com/en_eset-research_evasive-panda-leverages-monlam-festival-target-tibetans/content.txt#L269C143-L269C152highN/Ahttps://github.com/mthcht/awesome-lists
65\8766714F94DDmore_eggsMalwareoffensive_toolhttps://thedfirreport.com/2024/12/02/the-curious-case-of-an-egg-cellent-resume/n=highN/Ahttps://github.com/mthcht/awesome-lists
66\LokiLokiLockerRansomwareoffensive_toolhttps://blogs.blackberry.com/en/2022/03/lokilocker-ransomwarecriticalcommand observed schtasks /CREATE /SC ONLOGON /TN Loki /TR *https://github.com/mthcht/awesome-lists
67\LimeRAT-AdminLime-RATMalwareoffensive_toolhttps://github.com/NYAN-x-CAT/Lime-RAT/blob/87e189781c0aef0e84cabe2f8c2e7d8f5143e594/Project/Client/C_Installation.vb#L76criticalN/Ahttps://github.com/mthcht/ThreatHunting-Keywords/blob/main/tools/L-N/Lime-RAT.csv
68\NFUBffkLemonDuckMalwareoffensive_toolhttps://notes.netbytesec.com/2024/10/lemonduck-unleashes-cryptomining.htmlhighN/Ahttps://github.com/mthcht/awesome-lists
69\K0adickoadicC2offensive_toolhttps://github.com/Averroes/koadic/blob/97886ed570f31efff09d1e06c4a7ece2d9b6bd27/data/implant/persist/schtasks.js#L4C21-L4C27criticalN/Ahttps://github.com/mthcht/awesome-lists
70\Feedback_API_VS_Services_ClientKeyzetsu clipper variantMalwareoffensive_toolhttps://checkmarx.com/blog/new-technique-to-trick-developers-detected-in-an-open-source-supply-chain-attack/mediumN/Ahttps://github.com/mthcht/awesome-lists
71\TaterInvoke-TaterPrivilege Escalationoffensive_toolhttps://github.com/BC-SECURITY/Empire/blob/8aca42747da6cf2b0def7edede94586f6b3258e8/empire/server/data/module_source/privesc/Invoke-Tater.ps1#L101criticalPowerShell implementation of the Hot Potato Windows Privilege Escalation exploit from @breenmachine and @foxglovesechttps://github.com/mthcht/awesome-lists
72\\DefenderGraphicalProton backdoorMalwareoffensive_toolhttps://www.ic3.gov/CSA/2023/231213.pdfhighN/Ahttps://github.com/mthcht/awesome-lists
73\\defenderGraphicalProton backdoorMalwareoffensive_toolhttps://www.ic3.gov/CSA/2023/231213.pdfhighN/Ahttps://github.com/mthcht/awesome-lists
74\\Microsoft\\DefenderServiceGraphicalProton backdoorMalwareoffensive_toolhttps://www.ic3.gov/CSA/2023/231213.pdfhighN/Ahttps://github.com/mthcht/awesome-lists
75\\Microsoft\\Windows\\Application Experience\\StartupAppTaskCheckGraphicalProton backdoorMalwareoffensive_toolhttps://www.ic3.gov/CSA/2023/231213.pdfhighN/Ahttps://github.com/mthcht/awesome-lists
76\\Microsoft\\Windows\\Application Experience\\StartupAppTaskCkeckGraphicalProton backdoorMalwareoffensive_toolhttps://www.ic3.gov/CSA/2023/231213.pdfhighN/Ahttps://github.com/mthcht/awesome-lists
77\\Microsoft\\Windows\\ATPUpdGraphicalProton backdoorMalwareoffensive_toolhttps://www.ic3.gov/CSA/2023/231213.pdfhighN/Ahttps://github.com/mthcht/awesome-lists
78\\Microsoft\\Windows\\Data Integrity Scan\Data Integrity UpdateGraphicalProton backdoorMalwareoffensive_toolhttps://www.ic3.gov/CSA/2023/231213.pdfhighN/Ahttps://github.com/mthcht/awesome-lists
79\\Microsoft\\Windows\\DefenderUPDServiceGraphicalProton backdoorMalwareoffensive_toolhttps://www.ic3.gov/CSA/2023/231213.pdfhighN/Ahttps://github.com/mthcht/awesome-lists
80\\Microsoft\\Windows\\IISUpdateServiceGraphicalProton backdoorMalwareoffensive_toolhttps://www.ic3.gov/CSA/2023/231213.pdfhighN/Ahttps://github.com/mthcht/awesome-lists
81\\Microsoft\\Windows\\Speech\\SpeechModelInstallTaskGraphicalProton backdoorMalwareoffensive_toolhttps://www.ic3.gov/CSA/2023/231213.pdfhighN/Ahttps://github.com/mthcht/awesome-lists
82\\Microsoft\\Windows\\WiMSDFSGraphicalProton backdoorMalwareoffensive_toolhttps://www.ic3.gov/CSA/2023/231213.pdfhighN/Ahttps://github.com/mthcht/awesome-lists
83\\Microsoft\\Windows\\Windows Defender\\Defender Update ServiceGraphicalProton backdoorMalwareoffensive_toolhttps://www.ic3.gov/CSA/2023/231213.pdfhighN/Ahttps://github.com/mthcht/awesome-lists
84\\Microsoft\\Windows\\Windows Defender\\Service UpdateGraphicalProton backdoorMalwareoffensive_toolhttps://www.ic3.gov/CSA/2023/231213.pdfhighN/Ahttps://github.com/mthcht/awesome-lists
85\\Microsoft\\Windows\\Windows Error Reporting\\CheckReportingGraphicalProton backdoorMalwareoffensive_toolhttps://www.ic3.gov/CSA/2023/231213.pdfhighN/Ahttps://github.com/mthcht/awesome-lists
86\\Microsoft\\Windows\\Windows Error Reporting\\SubmitReportingGraphicalProton backdoorMalwareoffensive_toolhttps://www.ic3.gov/CSA/2023/231213.pdfhighN/Ahttps://github.com/mthcht/awesome-lists
87\\Microsoft\\Windows\\Windows Filtering Platform\\BfeOnServiceStartGraphicalProton backdoorMalwareoffensive_toolhttps://www.ic3.gov/CSA/2023/231213.pdfhighN/Ahttps://github.com/mthcht/awesome-lists
88\\Microsoft\\Windows\\WindowsDefenderServiceGraphicalProton backdoorMalwareoffensive_toolhttps://www.ic3.gov/CSA/2023/231213.pdfhighN/Ahttps://github.com/mthcht/awesome-lists
89\\Microsoft\\Windows\\WindowsDefenderService2GraphicalProton backdoorMalwareoffensive_toolhttps://www.ic3.gov/CSA/2023/231213.pdfhighN/Ahttps://github.com/mthcht/awesome-lists
90\\Microsoft\\Windows\\WindowsUpdate\\Scheduled AutoCheckGraphicalProton backdoorMalwareoffensive_toolhttps://www.ic3.gov/CSA/2023/231213.pdfhighN/Ahttps://github.com/mthcht/awesome-lists
91\\Microsoft\\Windows\\WindowsUpdate\\Scheduled CheckGraphicalProton backdoorMalwareoffensive_toolhttps://www.ic3.gov/CSA/2023/231213.pdfhighN/Ahttps://github.com/mthcht/awesome-lists
92\\WindowUpdateGraphicalProton backdoorMalwareoffensive_toolhttps://www.ic3.gov/CSA/2023/231213.pdfhighN/Ahttps://github.com/mthcht/awesome-lists
93\DefenderGraphicalProton backdoorMalwareoffensive_toolhttps://www.ic3.gov/CSA/2023/231213.pdfhighN/Ahttps://github.com/mthcht/awesome-lists
94\defenderGraphicalProton backdoorMalwareoffensive_toolhttps://www.ic3.gov/CSA/2023/231213.pdfhighN/Ahttps://github.com/mthcht/awesome-lists
95\Microsoft\DefenderServiceGraphicalProton backdoorMalwareoffensive_toolhttps://www.ic3.gov/CSA/2023/231213.pdfhighN/Ahttps://github.com/mthcht/awesome-lists
96\Microsoft\Windows\Application Experience\StartupAppTaskCheckGraphicalProton backdoorMalwareoffensive_toolhttps://www.ic3.gov/CSA/2023/231213.pdfhighN/Ahttps://github.com/mthcht/awesome-lists
97\Microsoft\Windows\Application Experience\StartupAppTaskCkeckGraphicalProton backdoorMalwareoffensive_toolhttps://www.ic3.gov/CSA/2023/231213.pdfhighN/Ahttps://github.com/mthcht/awesome-lists
98\Microsoft\Windows\ATPUpdGraphicalProton backdoorMalwareoffensive_toolhttps://www.ic3.gov/CSA/2023/231213.pdfhighN/Ahttps://github.com/mthcht/awesome-lists
99\Microsoft\Windows\Data Integrity Scan\Data Integrity UpdateGraphicalProton backdoorMalwareoffensive_toolhttps://www.ic3.gov/CSA/2023/231213.pdfhighN/Ahttps://github.com/mthcht/awesome-lists
100\Microsoft\Windows\DefenderUPDServiceGraphicalProton backdoorMalwareoffensive_toolhttps://www.ic3.gov/CSA/2023/231213.pdfhighN/Ahttps://github.com/mthcht/awesome-lists
101\Microsoft\Windows\IISUpdateServiceGraphicalProton backdoorMalwareoffensive_toolhttps://www.ic3.gov/CSA/2023/231213.pdfhighN/Ahttps://github.com/mthcht/awesome-lists
102\Microsoft\Windows\Speech\SpeechModelInstallTaskGraphicalProton backdoorMalwareoffensive_toolhttps://www.ic3.gov/CSA/2023/231213.pdfhighN/Ahttps://github.com/mthcht/awesome-lists
103\Microsoft\Windows\WiMSDFSGraphicalProton backdoorMalwareoffensive_toolhttps://www.ic3.gov/CSA/2023/231213.pdfhighN/Ahttps://github.com/mthcht/awesome-lists
104\Microsoft\Windows\Windows Defender\Defender Update ServiceGraphicalProton backdoorMalwareoffensive_toolhttps://www.ic3.gov/CSA/2023/231213.pdfhighN/Ahttps://github.com/mthcht/awesome-lists
105\Microsoft\Windows\Windows Defender\Service UpdateGraphicalProton backdoorMalwareoffensive_toolhttps://www.ic3.gov/CSA/2023/231213.pdfhighN/Ahttps://github.com/mthcht/awesome-lists
106\Microsoft\Windows\Windows Error Reporting\CheckReportingGraphicalProton backdoorMalwareoffensive_toolhttps://www.ic3.gov/CSA/2023/231213.pdfhighN/Ahttps://github.com/mthcht/awesome-lists
107\Microsoft\Windows\Windows Error Reporting\SubmitReportingGraphicalProton backdoorMalwareoffensive_toolhttps://www.ic3.gov/CSA/2023/231213.pdfhighN/Ahttps://github.com/mthcht/awesome-lists
108\Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStartGraphicalProton backdoorMalwareoffensive_toolhttps://www.ic3.gov/CSA/2023/231213.pdfhighN/Ahttps://github.com/mthcht/awesome-lists
109\Microsoft\Windows\WindowsDefenderServiceGraphicalProton backdoorMalwareoffensive_toolhttps://www.ic3.gov/CSA/2023/231213.pdfhighN/Ahttps://github.com/mthcht/awesome-lists
110\Microsoft\Windows\WindowsDefenderService2GraphicalProton backdoorMalwareoffensive_toolhttps://www.ic3.gov/CSA/2023/231213.pdfhighN/Ahttps://github.com/mthcht/awesome-lists
111\Microsoft\Windows\WindowsUpdate\Scheduled AutoCheckGraphicalProton backdoorMalwareoffensive_toolhttps://www.ic3.gov/CSA/2023/231213.pdfhighN/Ahttps://github.com/mthcht/awesome-lists
112\Microsoft\Windows\WindowsUpdate\Scheduled CheckGraphicalProton backdoorMalwareoffensive_toolhttps://www.ic3.gov/CSA/2023/231213.pdfhighN/Ahttps://github.com/mthcht/awesome-lists
113\WindowUpdateGraphicalProton backdoorMalwareoffensive_toolhttps://www.ic3.gov/CSA/2023/231213.pdfhighN/Ahttps://github.com/mthcht/awesome-lists
114\InfrSiRfucture TechnologiesGootloaderMalwareoffensive_toolhttps://thedfirreport.com/2024/02/26/seo-poisoning-to-domain-control-the-gootloader-saga-continues/criticalN/Ahttps://github.com/mthcht/awesome-lists
115\SynchronizeTimeZonefrpData Exfiltrationoffensive_toolhttps://www.aha.org/system/files/media/file/2021/05/fbi-flash-tlp-white-apt-actors-exploiting-fortinet-vulnerabilities-to-gain-access-for-malicious-activity-5-27-21.pdfhighAPT Actors Exploiting Fortinet Vulnerabilities to Gain Access for Malicious Activity - creating specific scheduled task for exfiltrationhttps://github.com/mthcht/awesome-lists
116\CursorSvcFentanyl StealerMalwareoffensive_toolhttps://github.com/dekrypted/Fentanyl/blob/2b4a008934f21df4eed7b90fb3019d3395f7c909/fenty.py#L699C53-L699C62criticalSimilar to Bandit Stealerhttps://github.com/mthcht/awesome-lists
117\DisableBitdefender-*DispossesorRansomwareoffensive_toolhttps://vx-underground.org/Archive/Dispossessor%20LeakshighN/Ahttps://github.com/mthcht/awesome-lists
118\DHARMADharmaRansomwareoffensive_toolhttps://www.joesandbox.com/analysis/860608/0/lighthtmlcriticalcommand observed schtasks /CREATE /SC ONLOGON /TN DHARMA /TR C:\ProgramData\harma.exe*https://github.com/mthcht/awesome-lists
119\SorryCryptominerCryptomineroffensive_toolhttps://x.com/cglyer/status/1001463072672886785highschtasks /create /tn 'Sorry' /tr C:\Windows\Temp\taskhost.exe /sc daily /mo 2 /st 22:00:00 /f4https://x.com/cglyer/status/1001463072672886785
120\shadowdevCobaltStrikeC2offensive_toolhttps://cloud.google.com/blog/topics/threat-intelligence/melting-unc2198-icedid-to-ransomware-operationscriticalcmd.exe /c schtasks /create /sc minute /mo 1 /tn shadowdev /tr C:\\ProgramData\\S\u0443sH\u0435\u0430ls\\T\u0430s\u0441host.exehttps://github.com/mthcht/awesome-lists
121\ClearEventLogsCleareventlog scriptDefense Evasionoffensive_toolhttps://x.com/GroupIB_DFIR/status/1750452304606810175highschtasks /create /tn ClearEventLogs /tr 'powershell.exe -Command wevtutil el | foreach { wevtutil cl $_ }' /sc daily /st 03:00 /ru SYSTEM /fhttps://github.com/mthcht/awesome-lists
122\SC Scheduled ScanChaferMalwareoffensive_toolhttps://nyotron.com/nyotron-discovers-next-generation-oilrig-attacks/highChafer activity attributed to OilRighttps://github.com/mthcht/awesome-lists
123\UpdatMachineChaferMalwareoffensive_toolhttps://nyotron.com/nyotron-discovers-next-generation-oilrig-attacks/highChafer activity attributed to OilRighttps://github.com/mthcht/awesome-lists
124\drogonBadRabbitMalwareoffensive_toolhttps://www.vmray.com/analyses/bad-rabbit-ransomware-flash-analysis/report/overview.htmlcriticalschtasks /Create /SC once /TN drogon /RU SYSTEM /TR 'C:\Windows\system32\shutdown.exe /r /t 0 /f' /ST 02:34:00https://github.com/mthcht/awesome-lists
125\BaiduUpdateTask1BADNEWSMalwareoffensive_toolhttps://unit42.paloaltonetworks.com/unit42-patchwork-continues-deliver-badnews-indian-subcontinent/highN/Ahttps://github.com/mthcht/awesome-lists
126\AutoRDPwnAutoRDPwnC2offensive_toolhttps://github.com/JoelGMSec/AutoRDPwn/blob/839d6afbd2cfa64b01a188b4e09a3e079c9c81d3/AutoRDPwn.ps1#L678criticalN/Ahttps://github.com/mthcht/awesome-lists
127\thepiratMicrosoftEdgeUpdateTaskAsyncRATMalwareoffensive_toolhttps://any.run/cybersecurity-blog/asyncrat-open-directories-infection-analysis/criticalAsyncRAT’s Infection sampleshttps://github.com/mthcht/awesome-lists
128\kbnvmmmhjoAgent TeslaMalwareoffensive_toolhttps://isc.sans.edu/diary/PowerPoint+attachments+Agent+Tesla+and+code+reuse+in+malware/28154criticalN/Ahttps://github.com/mthcht/awesome-lists