CCM.exe (SCCM)
Windows Config Manager CCM.exe runs b64-encoded powershell. The commands can be large enough to take multiple Event 4104 entries.
Categories: microsoft, windows, powershell
View authoritative reference βπ CRAWLABLE DATASET INDEX
Benign applications and services whose unusual behavior can resemble malicious activity or create detection noise.
Use these records to investigate possible false positives and tune detections without creating broad exclusions. Confirm product provenance and the complete behavior chain.
50 searchable entries. Open the interactive explorer β
Windows Config Manager CCM.exe runs b64-encoded powershell. The commands can be large enough to take multiple Event 4104 entries.
Categories: microsoft, windows, powershell
View authoritative reference βDo you like giant DNS queries? Sophos does. Sophos Web Protection, for reasons surpassing understanding, performs DNS lookups using b64-encoded data as subdomains to sophosxl.net. This creates a gigantic amount of DNS queries, all of which look like data exfil, because technically they are.
Categories: sophos, dns
View authoritative reference βWho doesn't love CScript? LogMeIn runs avfilter.js via cscript to check what AV is running on your system for some godawful reason. As far as I am aware, they have yet to provide any substantial documentation or reasoning as to why.
Categories: logmein, windows, cscript
View authoritative reference βHow to look like malware, by RingCentral Binary installs deep in AppData, drops a setDefaultAppByProtcol.vbs script, that is then executed to query/create/modify registry entries by running cmd.exe to call cscript //NoLogo and then finally run the vbscript.
Categories: ringcentral, windows, cscript, vbscript
View authoritative reference βNot the Bloodhound you're thinking of. Silver Bullet Technology's Ranger runs an executable called Bloodhound.exe (C:\Program Files (x86)\Silver Bullet Technology\Ranger\Logging\Bloodhound.exe). It doesn't appear to be SpecterOps's Bloodhound tool for Active Directory mapping, it merely shares a namesake.
Categories: windows, silverbullet, bloodhound
View authoritative reference βNamed after legitimate Windows binaries, in the wrong location. They were spawned in succession from C:\Program Files (x86)\noregon\JPRO diagnostics\Fleets.exe > C:\Program Files (x86)\noregon\JPRO diagnosticsjprostart.exe > C:\Users\AppData\Local\icsys.icn.exe > c:\Windows\System\explorer.exe > C:\Windows\System\spoolsv.exe > C:\Windows\System\svchost.exe. The files are custom binaries compiled with Visual Basic. They appear to be changed/created regularly as the hashes seem to change often.
Categories: windows, noregon, fake
View authoritative reference βA little LSASS, as a treat. Adobe Genuine Monitor Service (AGMService.exe) opens and reads from the LSASS process. While this access is legitimate, it can create false positives for process access alerts.
Categories: windows, adobe, lsass
View authoritative reference βIvanti does some weird stuff The command-line arguments for the exes listed below occasionally contain fragmented, seemingly-random strings containing special unicode characters, what looks like bits of HTML or XML tags, and/or URL-enocoded strings. For example: LDdrives.exe -p 51205 -c -s -b5Dβ¬ Cv LDdrives.exe -p 51205 -c -s -b8Β΅q LDdrives.exe -p 51205 -c -s "-b8</timer>ΒΆ(+N& " LDmemory.exe -p 51207 -c -s "-b32164/><key nam=ΓgΓo " LDnetwork.exe -p 51214 -c -s -b10</timer>ΕΎΓ/β¬/ These processes all spawn instances of Console Host (conhost.exe) with the 0x4 flag, like C:\Windows\system32\conhost.exe 0x4.
Categories: windows, ivanti
View authoritative reference βEDRs π€ Malware Encoded PowerShell A legitimate PowerShell script associated with SentinelOne includes encoded PowerShell, AMSI bypass encoding, as well as strings for offensive security commands such as Invoke-Mimikatz. If running another security solutionβlike Defenderβit may flag this SentinelOne legitimate PowerShell activity as malicious.
Categories: sentinelone, powershell
View authoritative reference βYet another PowerShell weirdo. Snow Inventory Agent for Windows (snowagent.exe) runs PowerShell which resembles shellcode (bindshell) powershell.exe -command Invoke-Expression byte arrays string encoding operations pipes.
Categories: windows, snow, powershell
View authoritative reference βBizarre DNS requests on Samsung phones. Samsung MobileWips (presumably a Wireless Intrusion Prevention System) is a default system app on certain Android OS versions. It has been observed making DNS requests to google.com.onion, which will trigger network/DNS-related alerts, such as the Sigma rule Query Tor Onion Address. This domain does not resolve to an IP address, and is not accessible via Tor. It appears to have been added as some sort of DNS check by an Android developer with poor taste!
Categories: android, tor
View authoritative reference βPalo Alto GP Firewall HIP check runs whoami.exe as SYSTEM.
Categories: paloalto, vpn, cmd, whoami
View authoritative reference βNot just bad guys run whoami. ArcGISPortal.exe runs whoami.exe. I know other Defenders have been caught out by this weird activity. But, ArcGIS spawning whoami is completely legitimate and authorised activity. Huntress telemetry shows 60,000 in the last 15 hours. I would advice adding this very specific activity to an ignore list, so it does not trigger a detection.
Categories: arcgis, windows, whoami
View authoritative reference βMcAfee also loves big DNS queries! Various McAfee performs odd DNS lookups to subdomains of avqs.mcafee.com and avts.mcafee.com domains. Example: A? a-0.19-a3000081.c930082.1838.11b0.2fca.400.0.n7dbrrk87wfrd2gm1699ghv8hi.avqs.mcafee.com. A? 13-0.19-b3000081.30483.1838.11b4.2fca.210.0.jsdhk1cfzc4r9jrf2j214zd4gi.avqs.mcafee.com. A? 13-0.19-b3000081.a0082.1838.11b4.2fca.210.0.4fk9i42wg1l1rlfrgvlpsv7a9q.avqs.mcafee.com. A? 13-0.19-b3000081.60082.1838.11b4.2fca.210.0.uqnk1rubb52k9unam8919hj6wq.avqs.mcafee.com. A? 13-0.19-b3000081.8a70082.1838.11b4.2fca.210.0.bklpbm2z81gc949wv8qr3spea6.avqs.mcafee.com. A? 13-0.19-b3000081.60082.1838.11b4.2fca.210.0.nuthnwa7a65azzqaij3t43ts1i.avqs.mcafee.com. A? 13-0.19-b3000081.60082.1838.11b4.2fca.210.0.lqmag7m5gq7i6h16d6emea6fwv.avqs.mcafee.com. A? 13-0.19-b3000081.10082.1838.11b4.2fca.210.0.gkmrckah4wcjc96fvbratcmn26.avqs.mcafee.com. A? 14-0.19-b3000489.2.1644.95b.3ea3.210.0.7ahnlkt1uiliactc2cfvqqnjcv.avts.mcafee.com.
Categories: mcafee, windows, dns
View authoritative reference βEverybody loves a big DNS query! Various modules of ESET protection suite (Antispam, Parental Controls, LiveGrid) perform odd DNS lookups to subdomains of e5.sk domain. Example: TXT? oa5jhh3yxkgu5kpwgnjmgk54pubqeaqbaeaq.a.e.e5.sk. TXT? wzxh7gqaszmunhqg3g5ouiiuwebqeaqbaeaq.a.e.e5.sk. TXT? xegjkvpuklfebhejqeve4mltsmbqeaqbaeaq.a.e.e5.sk. TXT? vscxkxbn55aelaru6a6y3dxznebqeaqbaeaq.a.e.e5.sk. TXT? dc5wtaihc6luvphgub6laccokebqeaqbaeaq.a.e.e5.sk.
Categories: eset, windows, dns
View authoritative reference βEaseUS and bizarre Scheduled Tasks. The file is associated with EaseUS Partition Manager or Hard Drive Tools 2003 by TradeTouch.com. Aside from the odd name of the binary, other WTF behaviors include installing to system32 and creating scheduled tasks. These stand out when triaging in PowerShell using Get-ScheduledTask | Select -Property Author
Categories: easeus, windows, scheduledtask
View authoritative reference βAvast scans your network on the sly. During scans, AvastSvc.exe will attempt to connect to neighboring IP addresses over SSH. Users such as FakeDomain\FakeUser will be used, as well as blank users/null SIDs.
Categories: avast, windows, ssh
View authoritative reference βSenseNDR base64 encoding SenseNDR, a component of Microsoft Defender for Endpoint, encodes data for transmission in massive base64 chunks.
Categories: microsoft, windows, defender
View authoritative reference βWhoami? HostedAgent, of course! Trend Micro WFBS Agent runs whoami.exe regularly as SYSTEM for reasons unknown.
Categories: trendmicro, windows, whoami
View authoritative reference βRandom file extensions from iManage When Office documents are protected by iManage, upon opening them they create script files in %TEMP% with a randomly generated file extension (such as .hta, .sct, .inf, .cpl, .wsf, etc.). This happens because iManage implements the Path.GetRandomFileName Method to handle this behavior. So while most instances result in files that look like x191krbu.idj, sometimes they end up being written like x191krbu.hta which likely will wreak havoc on a good defender's SIEM rules.
Categories: imanage, windows
View authoritative reference βBase64-encoded PowerShell from Azure's own agent! The Azure Connected Machine Agent spawns a process that runs encoded Powershell strings. Triggers when the agent downloads new policies from Azure.
Categories: azure, windows, powershell
View authoritative reference βGuests are not invited to Everyone shares. Sharing a Windows folder with Everyone permissions, will cause a failed logon of user Guest.
Categories: windows, explorer
View authoritative reference βIt runs whoami because it's lost.
Categories: microsoft, whoami, cmd
View authoritative reference βHow much can an EDR look like malware? Microsoft Defender Advanced Threat Protection uses SenseIR.exe to launch Powershell scripts that then uses .NET function [System.IO.File]::Open() to read another Powershell script into memory for execution. The second Powershell script executed has its parameters passed in as base64-encoded text.
Categories: windows, defender, base64
View authoritative reference βYet another base64-loving process. In this case, the encoded commands are also WMI PowerShell commands.
Categories: windows, nutanix, base64
View authoritative reference βCisco enumerates your system. CiscoJabberPrt.exe will pipe ipconfig.exe /all, systeminfo.exe, and tasklist.exe into a file named Systeminfo.txt inside of the User's %TEMP% folder.
Categories: windows, cisco, filewrite
View authoritative reference βWindows being sus? Inconceivable! Windows executes a suspiciously named DLL export with a name of SusRunTask, and this DLL checks many various Scheduled Task and Autostart execution locations, such as Registry persistence locations and C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\, as well as spawning new processes that are not child processes.
Categories: windows, dll
View authoritative reference βIBM creates WMI false positives The data collector periodically runs a command like: cmd.exe /c wmic process call create C:\...\datacollectorbin\collectorSrvWatchDog.bat. This may trigger detection rules geared towards T1047: Windows Management Instrumentation which look for wmic.exe being used to covertly spawn processes.
Categories: windows, ibm, wmi
View authoritative reference βJetBrains queries security tools. idea64.exe and rider64.exe from JetBrains query the installed antivirus product in the exact same way that malicious programs do using the command: wmic /namespace:\\root\securitycenter2 path antivirusproduct get displayname,productstate
Categories: windows, jetbrains, wmi
View authoritative reference βNacho dwm Teramind installs its own dwm.exe file inside a subfolder of C:\ProgramData\{4cec2908-5ce4-48f0-a717-8fc833d8017a}.
Categories: windows, teramind
View authoritative reference βIBM's pcsnp.exe just...what IBM's pcsnp.exe calls cmd.exe /c mkdir C:\Temp from processes such as mpnotify.exe and lsass.exe. Read the writeup for this; it's amazing.
Categories: windows, cmd, ibm
View authoritative reference βTFW the vuln scanner runs offensive tools. When connecting to Windows hosts, OpenVAS will run impacket-wmiexec against the host. The resulting events look identical to a secretsdump run that you'd hunt for.
Categories: windows, impacket, greenbone, openvas
View authoritative reference βWho needs protection? Not LSA! Sets HKLM\SYSTEM\CurrentControlSet\Control\Lsa\RunAsPPL to 0 (= insecure = might raise EDR alerts ahem ahem) just before setting it (back?) to 2 for no valid reason.
Categories: windows, lsass
View authoritative reference βThe Nim language installer binaries in certain versions trigger Windows Defender. These include nimble.exe, finish.exe, koch.exe, and other binaries that come packaged during a stock install of Nim.
Categories: nim, windows, defender
View authoritative reference βNothing to see here draw.io.exe uses attrib.exe to hide the file .dtmp using the command attrib +h filename.dtmp.
Categories: windows, draw.io
View authoritative reference βA little wmic enumeration Trend Micro EndpointBasecamp.exe drops RiskIndexCollector.exe which invoke wmic to get list of Hotfixes/Patches using the command wmic qfe get Description, HotfixID, InstalledOn
Categories: windows, trendmicro, wmi
View authoritative reference βWhat is it with antivirus and weird DNS? ESET NOD32 Antivirus kernel (ekrn.exe) performs random-looking Domain Name lookups.
Categories: windows, eset, dns
View authoritative reference βMicrosoft loves to look like malware, huh? Microsoft Management Services Cloud Managed Desktop Agent runs b64 PowerShell.
Categories: windows, microsoft, powershell
View authoritative reference βAnother bin with an identity crisis. Microsoft Management Services Cloud Managed Desktop Agent runs b64 PowerShell.
Categories: windows, whoami, symantec
View authoritative reference βAdobe performs...process injection?? Adobe Creative Cloud setup spawns and injects code to explorer.exe for deleting itself. The injected function calls WaitForSingleObject(INFINITE) on the injector's process duplicated handle, then CloseHandle it, follows to loop over DeleteFileW to retry while it fails with an inner Sleep(1000) until success, then calls ExitProcess(0).
Categories: adobe, windows, process injection
View authoritative reference βPodman Desktop writes .vbs to the Startup folder. After installation, Podman Desktop.exe creates a .vbs file using WScript.exe and pushes it to the Startup folder on Windows.
Categories: podman, windows, vbs, wscript
View authoritative reference βIP Geo-Location Extension Attribute Closely Resembles Keylogger Behavior Jamf Extension Attributes are used to add extra contextual info to devices managed within Jamf Connect MDM. These extension attributes are defined in an XML format. One commonly-used extension attribute, IP Geo-location, available on Jamf Github here, uses curl requests to extract IP location information in the exact same way as Nova Logger, a recent variant of Snake Keylogger. This includes the commands: curl -L -s --max-time 10 http://checkip.dyndns.org and curl -L -s --max-time 10 http://freegeoip.net/xml/<ipaddress>. Note: Nova Logger uses reallyfreegeoip[.]org to get the country name of the victim device (slightly different domain).
Categories: macos, curl, jamf
View authoritative reference βpia-daemon emits 'ICMP Flood' behavior every minute. This is a 'latency check' which is used for server selection. pia-daemon emits 'ICMP Flood' behavior every minute. This is a 'latency check' which is used for server selection. This occurs when PIA is installed & disconnected. The GUI/frontend is not required to be running, only the pia-daemon. Unifi IPS detects some IPs from this latency check as IPS Alert 2: Misc Attack. Signature ET CINS Active Threat Intelligence Poor Reputation IP group 46. From: <source ip>:0, to: <dest ip>:0, protocol: ICMP
Categories: private internet access
View authoritative reference βThe Block64 Discovery Agent uses Impacket's psexec module, scaring SOC analysts everywhere when it's deployed.
Categories: zendesk, block64, windows
View authoritative reference βWindows uses random high service ports for a variety of functions. Without knowing this, these connections seem malicious but should be considered benign without a second source of suspicion.
Categories: network, windows, microsoft
View authoritative reference βServices created as part of this application installation and usage will create or rename files with a .crypt extension. According to mthcht's Awesome List of Ransomware Extensions, the .crypt extension is associated with FindZip ransomware. Initiating processes observed creating or renaming the .crypt files include backgroundtaskhost.exe, setuphost.exe, and svchost.exe.
Categories: windows, dts
View authoritative reference βBizarre sub-processes. Browsers based on Chromium will launch several sub-processes that look extremely suspicious, with command-line options like --utility and --utility-sub-type=unzip.mojom.Unzipper. Despite Google searches for these terms matching malware analysis reports, these are expected behaviors.
Categories: chrome, edge, windows, linux, commandline
View authoritative reference βWindows Terminal runs wsl on startup. Upon launch, Windows Terminal runs wsl --list to find potential Linux profiles to add to its list.
Categories: windows, microsoft, commandline
View authoritative reference βWMIExec-ish NDCC The executable for Network Detective Data Collector displays false positive activity similar to Impacket's WMI/SMBexec.
Categories: windows, network, impacket
View authoritative reference βAdobe Reader for no reason starts a subprocess using the command line "I run".
Categories: adobe, windows, commandline
View authoritative reference β