Evasive program files directory name

This was a great share by @subtee about misleading directory names and worthy of a quick sig.

I needed a few more tunes than shown but this is the general idea.

Evasive program files directory name


I add the md5 to the table for quick review if I get any hits.


References:
https://twitter.com/subTee/status/1187037543260274688

Comments

Popular posts from this blog

Misleading extensions Xls.exe Doc.exe Pdf.exe

Netconn from suspicious directories

Powershell DNS C2 Notes