← LOTL Reference home

πŸ”Ž CRAWLABLE DATASET INDEX

WTFBins

Benign applications and services whose unusual behavior can resemble malicious activity or create detection noise.

Use these records to investigate possible false positives and tune detections without creating broad exclusions. Confirm product provenance and the complete behavior chain.

50 searchable entries. Open the interactive explorer β†’

CCM.exe (SCCM)

Windows Config Manager CCM.exe runs b64-encoded powershell. The commands can be large enough to take multiple Event 4104 entries.

Categories: microsoft, windows, powershell

View authoritative reference β†—

Sophos Web Protection (sophosxl.net)

Do you like giant DNS queries? Sophos does. Sophos Web Protection, for reasons surpassing understanding, performs DNS lookups using b64-encoded data as subdomains to sophosxl.net. This creates a gigantic amount of DNS queries, all of which look like data exfil, because technically they are.

Categories: sophos, dns

View authoritative reference β†—

LogMeIn and CScript

Who doesn't love CScript? LogMeIn runs avfilter.js via cscript to check what AV is running on your system for some godawful reason. As far as I am aware, they have yet to provide any substantial documentation or reasoning as to why.

Categories: logmein, windows, cscript

View authoritative reference β†—

RingCentral.exe

How to look like malware, by RingCentral Binary installs deep in AppData, drops a setDefaultAppByProtcol.vbs script, that is then executed to query/create/modify registry entries by running cmd.exe to call cscript //NoLogo and then finally run the vbscript.

Categories: ringcentral, windows, cscript, vbscript

View authoritative reference β†—

Bloodhound.exe

Not the Bloodhound you're thinking of. Silver Bullet Technology's Ranger runs an executable called Bloodhound.exe (C:\Program Files (x86)\Silver Bullet Technology\Ranger\Logging\Bloodhound.exe). It doesn't appear to be SpecterOps's Bloodhound tool for Active Directory mapping, it merely shares a namesake.

Categories: windows, silverbullet, bloodhound

View authoritative reference β†—

Noregon Fake Windows Components

Named after legitimate Windows binaries, in the wrong location. They were spawned in succession from C:\Program Files (x86)\noregon\JPRO diagnostics\Fleets.exe > C:\Program Files (x86)\noregon\JPRO diagnosticsjprostart.exe > C:\Users\AppData\Local\icsys.icn.exe > c:\Windows\System\explorer.exe > C:\Windows\System\spoolsv.exe > C:\Windows\System\svchost.exe. The files are custom binaries compiled with Visual Basic. They appear to be changed/created regularly as the hashes seem to change often.

Categories: windows, noregon, fake

View authoritative reference β†—

Adobe Genuine Monitor Service

A little LSASS, as a treat. Adobe Genuine Monitor Service (AGMService.exe) opens and reads from the LSASS process. While this access is legitimate, it can create false positives for process access alerts.

Categories: windows, adobe, lsass

View authoritative reference β†—

Ivanti Endpoint Manager

Ivanti does some weird stuff The command-line arguments for the exes listed below occasionally contain fragmented, seemingly-random strings containing special unicode characters, what looks like bits of HTML or XML tags, and/or URL-enocoded strings. For example: LDdrives.exe -p 51205 -c -s -b5D€ Cv LDdrives.exe -p 51205 -c -s -b8Β΅q LDdrives.exe -p 51205 -c -s "-b8</timer>ΒΆ(+N& " LDmemory.exe -p 51207 -c -s "-b32164/><key nam=Γ‚gΓ‹o " LDnetwork.exe -p 51214 -c -s -b10</timer>žÊ/€/ These processes all spawn instances of Console Host (conhost.exe) with the 0x4 flag, like C:\Windows\system32\conhost.exe 0x4.

Categories: windows, ivanti

View authoritative reference β†—

SentinelOne

EDRs 🀝 Malware Encoded PowerShell A legitimate PowerShell script associated with SentinelOne includes encoded PowerShell, AMSI bypass encoding, as well as strings for offensive security commands such as Invoke-Mimikatz. If running another security solutionβ€”like Defenderβ€”it may flag this SentinelOne legitimate PowerShell activity as malicious.

Categories: sentinelone, powershell

View authoritative reference β†—

Snow Inventory Agent for Windows

Yet another PowerShell weirdo. Snow Inventory Agent for Windows (snowagent.exe) runs PowerShell which resembles shellcode (bindshell) powershell.exe -command Invoke-Expression byte arrays string encoding operations pipes.

Categories: windows, snow, powershell

View authoritative reference β†—

Samsung MobileWips

Bizarre DNS requests on Samsung phones. Samsung MobileWips (presumably a Wireless Intrusion Prevention System) is a default system app on certain Android OS versions. It has been observed making DNS requests to google.com.onion, which will trigger network/DNS-related alerts, such as the Sigma rule Query Tor Onion Address. This domain does not resolve to an IP address, and is not accessible via Tor. It appears to have been added as some sort of DNS check by an Android developer with poor taste!

Categories: android, tor

View authoritative reference β†—

ArcGISPortal.exe

Not just bad guys run whoami. ArcGISPortal.exe runs whoami.exe. I know other Defenders have been caught out by this weird activity. But, ArcGIS spawning whoami is completely legitimate and authorised activity. Huntress telemetry shows 60,000 in the last 15 hours. I would advice adding this very specific activity to an ignore list, so it does not trigger a detection.

Categories: arcgis, windows, whoami

View authoritative reference β†—

McAfee Antivirus

McAfee also loves big DNS queries! Various McAfee performs odd DNS lookups to subdomains of avqs.mcafee.com and avts.mcafee.com domains. Example: A? a-0.19-a3000081.c930082.1838.11b0.2fca.400.0.n7dbrrk87wfrd2gm1699ghv8hi.avqs.mcafee.com. A? 13-0.19-b3000081.30483.1838.11b4.2fca.210.0.jsdhk1cfzc4r9jrf2j214zd4gi.avqs.mcafee.com. A? 13-0.19-b3000081.a0082.1838.11b4.2fca.210.0.4fk9i42wg1l1rlfrgvlpsv7a9q.avqs.mcafee.com. A? 13-0.19-b3000081.60082.1838.11b4.2fca.210.0.uqnk1rubb52k9unam8919hj6wq.avqs.mcafee.com. A? 13-0.19-b3000081.8a70082.1838.11b4.2fca.210.0.bklpbm2z81gc949wv8qr3spea6.avqs.mcafee.com. A? 13-0.19-b3000081.60082.1838.11b4.2fca.210.0.nuthnwa7a65azzqaij3t43ts1i.avqs.mcafee.com. A? 13-0.19-b3000081.60082.1838.11b4.2fca.210.0.lqmag7m5gq7i6h16d6emea6fwv.avqs.mcafee.com. A? 13-0.19-b3000081.10082.1838.11b4.2fca.210.0.gkmrckah4wcjc96fvbratcmn26.avqs.mcafee.com. A? 14-0.19-b3000489.2.1644.95b.3ea3.210.0.7ahnlkt1uiliactc2cfvqqnjcv.avts.mcafee.com.

Categories: mcafee, windows, dns

View authoritative reference β†—

ESET Protection Suite

Everybody loves a big DNS query! Various modules of ESET protection suite (Antispam, Parental Controls, LiveGrid) perform odd DNS lookups to subdomains of e5.sk domain. Example: TXT? oa5jhh3yxkgu5kpwgnjmgk54pubqeaqbaeaq.a.e.e5.sk. TXT? wzxh7gqaszmunhqg3g5ouiiuwebqeaqbaeaq.a.e.e5.sk. TXT? xegjkvpuklfebhejqeve4mltsmbqeaqbaeaq.a.e.e5.sk. TXT? vscxkxbn55aelaru6a6y3dxznebqeaqbaeaq.a.e.e5.sk. TXT? dc5wtaihc6luvphgub6laccokebqeaqbaeaq.a.e.e5.sk.

Categories: eset, windows, dns

View authoritative reference β†—

EaseUS spaceman.exe

EaseUS and bizarre Scheduled Tasks. The file is associated with EaseUS Partition Manager or Hard Drive Tools 2003 by TradeTouch.com. Aside from the odd name of the binary, other WTF behaviors include installing to system32 and creating scheduled tasks. These stand out when triaging in PowerShell using Get-ScheduledTask | Select -Property Author

Categories: easeus, windows, scheduledtask

View authoritative reference β†—

AvastSvc.exe

Avast scans your network on the sly. During scans, AvastSvc.exe will attempt to connect to neighboring IP addresses over SSH. Users such as FakeDomain\FakeUser will be used, as well as blank users/null SIDs.

Categories: avast, windows, ssh

View authoritative reference β†—

SenseNdr.exe

SenseNDR base64 encoding SenseNDR, a component of Microsoft Defender for Endpoint, encodes data for transmission in massive base64 chunks.

Categories: microsoft, windows, defender

View authoritative reference β†—

HostedAgent.exe

Whoami? HostedAgent, of course! Trend Micro WFBS Agent runs whoami.exe regularly as SYSTEM for reasons unknown.

Categories: trendmicro, windows, whoami

View authoritative reference β†—

iManage Document Protection

Random file extensions from iManage When Office documents are protected by iManage, upon opening them they create script files in %TEMP% with a randomly generated file extension (such as .hta, .sct, .inf, .cpl, .wsf, etc.). This happens because iManage implements the Path.GetRandomFileName Method to handle this behavior. So while most instances result in files that look like x191krbu.idj, sometimes they end up being written like x191krbu.hta which likely will wreak havoc on a good defender's SIEM rules.

Categories: imanage, windows

View authoritative reference β†—

gc_worker.exe

Base64-encoded PowerShell from Azure's own agent! The Azure Connected Machine Agent spawns a process that runs encoded Powershell strings. Triggers when the agent downloads new policies from Azure.

Categories: azure, windows, powershell

View authoritative reference β†—

explorer.exe

Guests are not invited to Everyone shares. Sharing a Windows folder with Everyone permissions, will cause a failed logon of user Guest.

Categories: windows, explorer

View authoritative reference β†—

SenseIR.exe

How much can an EDR look like malware? Microsoft Defender Advanced Threat Protection uses SenseIR.exe to launch Powershell scripts that then uses .NET function [System.IO.File]::Open() to read another Powershell script into memory for execution. The second Powershell script executed has its parameters passed in as base64-encoded text.

Categories: windows, defender, base64

View authoritative reference β†—

Nutanix Guest Tools

Yet another base64-loving process. In this case, the encoded commands are also WMI PowerShell commands.

Categories: windows, nutanix, base64

View authoritative reference β†—

Cisco Jabber

Cisco enumerates your system. CiscoJabberPrt.exe will pipe ipconfig.exe /all, systeminfo.exe, and tasklist.exe into a file named Systeminfo.txt inside of the User's %TEMP% folder.

Categories: windows, cisco, filewrite

View authoritative reference β†—

Startupscan.dll

Windows being sus? Inconceivable! Windows executes a suspiciously named DLL export with a name of SusRunTask, and this DLL checks many various Scheduled Task and Autostart execution locations, such as Registry persistence locations and C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\, as well as spawning new processes that are not child processes.

Categories: windows, dll

View authoritative reference β†—

IBM Storage Insights Data Collector

IBM creates WMI false positives The data collector periodically runs a command like: cmd.exe /c wmic process call create C:\...\datacollectorbin\collectorSrvWatchDog.bat. This may trigger detection rules geared towards T1047: Windows Management Instrumentation which look for wmic.exe being used to covertly spawn processes.

Categories: windows, ibm, wmi

View authoritative reference β†—

JetBrains binaries invoke WMI

JetBrains queries security tools. idea64.exe and rider64.exe from JetBrains query the installed antivirus product in the exact same way that malicious programs do using the command: wmic /namespace:\\root\securitycenter2 path antivirusproduct get displayname,productstate

Categories: windows, jetbrains, wmi

View authoritative reference β†—

Teramind's dwm.exe

Nacho dwm Teramind installs its own dwm.exe file inside a subfolder of C:\ProgramData\{4cec2908-5ce4-48f0-a717-8fc833d8017a}.

Categories: windows, teramind

View authoritative reference β†—

IBM's pcsnp.exe triggers SYSTEM cmd.exe

IBM's pcsnp.exe just...what IBM's pcsnp.exe calls cmd.exe /c mkdir C:\Temp from processes such as mpnotify.exe and lsass.exe. Read the writeup for this; it's amazing.

Categories: windows, cmd, ibm

View authoritative reference β†—

OpenVAS runs WMIExec

TFW the vuln scanner runs offensive tools. When connecting to Windows hosts, OpenVAS will run impacket-wmiexec against the host. The resulting events look identical to a secretsdump run that you'd hunt for.

Categories: windows, impacket, greenbone, openvas

View authoritative reference β†—

SecurityHealthService.exe unprotects LSA

Who needs protection? Not LSA! Sets HKLM\SYSTEM\CurrentControlSet\Control\Lsa\RunAsPPL to 0 (= insecure = might raise EDR alerts ahem ahem) just before setting it (back?) to 2 for no valid reason.

Categories: windows, lsass

View authoritative reference β†—

Nim Lang install binaries

The Nim language installer binaries in certain versions trigger Windows Defender. These include nimble.exe, finish.exe, koch.exe, and other binaries that come packaged during a stock install of Nim.

Categories: nim, windows, defender

View authoritative reference β†—

draw.io.exe

Nothing to see here draw.io.exe uses attrib.exe to hide the file .dtmp using the command attrib +h filename.dtmp.

Categories: windows, draw.io

View authoritative reference β†—

EndpointBasecamp.exe, RiskIndexCollector.exe

A little wmic enumeration Trend Micro EndpointBasecamp.exe drops RiskIndexCollector.exe which invoke wmic to get list of Hotfixes/Patches using the command wmic qfe get Description, HotfixID, InstalledOn

Categories: windows, trendmicro, wmi

View authoritative reference β†—

ESET AV Module (ekrn.exe)

What is it with antivirus and weird DNS? ESET NOD32 Antivirus kernel (ekrn.exe) performs random-looking Domain Name lookups.

Categories: windows, eset, dns

View authoritative reference β†—

Microsoft Managed Desktop Agent

Microsoft loves to look like malware, huh? Microsoft Management Services Cloud Managed Desktop Agent runs b64 PowerShell.

Categories: windows, microsoft, powershell

View authoritative reference β†—

Veritas Backup Agent (Symantec)

Another bin with an identity crisis. Microsoft Management Services Cloud Managed Desktop Agent runs b64 PowerShell.

Categories: windows, whoami, symantec

View authoritative reference β†—

Adobe CC Setup

Adobe performs...process injection?? Adobe Creative Cloud setup spawns and injects code to explorer.exe for deleting itself. The injected function calls WaitForSingleObject(INFINITE) on the injector's process duplicated handle, then CloseHandle it, follows to loop over DeleteFileW to retry while it fails with an inner Sleep(1000) until success, then calls ExitProcess(0).

Categories: adobe, windows, process injection

View authoritative reference β†—

Podman Desktop

Podman Desktop writes .vbs to the Startup folder. After installation, Podman Desktop.exe creates a .vbs file using WScript.exe and pushes it to the Startup folder on Windows.

Categories: podman, windows, vbs, wscript

View authoritative reference β†—

Jamf Nation

IP Geo-Location Extension Attribute Closely Resembles Keylogger Behavior Jamf Extension Attributes are used to add extra contextual info to devices managed within Jamf Connect MDM. These extension attributes are defined in an XML format. One commonly-used extension attribute, IP Geo-location, available on Jamf Github here, uses curl requests to extract IP location information in the exact same way as Nova Logger, a recent variant of Snake Keylogger. This includes the commands: curl -L -s --max-time 10 http://checkip.dyndns.org and curl -L -s --max-time 10 http://freegeoip.net/xml/<ipaddress>. Note: Nova Logger uses reallyfreegeoip[.]org to get the country name of the victim device (slightly different domain).

Categories: macos, curl, jamf

View authoritative reference β†—

pia-daemon ICMP Flood

pia-daemon emits 'ICMP Flood' behavior every minute. This is a 'latency check' which is used for server selection. pia-daemon emits 'ICMP Flood' behavior every minute. This is a 'latency check' which is used for server selection. This occurs when PIA is installed & disconnected. The GUI/frontend is not required to be running, only the pia-daemon. Unifi IPS detects some IPs from this latency check as IPS Alert 2: Misc Attack. Signature ET CINS Active Threat Intelligence Poor Reputation IP group 46. From: <source ip>:0, to: <dest ip>:0, protocol: ICMP

Categories: private internet access

View authoritative reference β†—

Block64 Uses Impacket

The Block64 Discovery Agent uses Impacket's psexec module, scaring SOC analysts everywhere when it's deployed.

Categories: zendesk, block64, windows

View authoritative reference β†—

Windows TCP Connections on High Ports

Windows uses random high service ports for a variety of functions. Without knowing this, these connections seem malicious but should be considered benign without a second source of suspicion.

Categories: network, windows, microsoft

View authoritative reference β†—

DTS Sound Unbound Ransomware File Extension

Services created as part of this application installation and usage will create or rename files with a .crypt extension. According to mthcht's Awesome List of Ransomware Extensions, the .crypt extension is associated with FindZip ransomware. Initiating processes observed creating or renaming the .crypt files include backgroundtaskhost.exe, setuphost.exe, and svchost.exe.

Categories: windows, dts

View authoritative reference β†—

Edge/Chromium Browsers

Bizarre sub-processes. Browsers based on Chromium will launch several sub-processes that look extremely suspicious, with command-line options like --utility and --utility-sub-type=unzip.mojom.Unzipper. Despite Google searches for these terms matching malware analysis reports, these are expected behaviors.

Categories: chrome, edge, windows, linux, commandline

View authoritative reference β†—

Windows Terminal

Windows Terminal runs wsl on startup. Upon launch, Windows Terminal runs wsl --list to find potential Linux profiles to add to its list.

Categories: windows, microsoft, commandline

View authoritative reference β†—

Network Detective Data Collector (nddc.exe)

WMIExec-ish NDCC The executable for Network Detective Data Collector displays false positive activity similar to Impacket's WMI/SMBexec.

Categories: windows, network, impacket

View authoritative reference β†—

Adobe Reader (reader_sl.exe)

Adobe Reader for no reason starts a subprocess using the command line "I run".

Categories: adobe, windows, commandline

View authoritative reference β†—