Skip to content

Instantly share code, notes, and snippets.

@MHaggis
Created September 28, 2021 21:15
Show Gist options
  • Save MHaggis/dc1f1c2ebbe884bb27065479321b06b8 to your computer and use it in GitHub Desktop.
Save MHaggis/dc1f1c2ebbe884bb27065479321b06b8 to your computer and use it in GitHub Desktop.
17ae38f1.profile:177: set spawnto_x86 "%windir%\\syswow64\\regsvr32.exe";
17ae38f1.profile:178: set spawnto_x64 "%windir%\\sysnative\\regsvr32.exe";
5d93e051.profile:167: set spawnto_x86 "%windir%\\syswow64\\regsvr32.exe";
5d93e051.profile:168: set spawnto_x64 "%windir%\\sysnative\\regsvr32.exe";
ACHLYS.profile:282:## spawnto_x86 %windir%\\syswow64\\rundll32.exe
ACHLYS.profile:283:## spawnto_x64 %windir%\\sysnative\\rundll32.exe
ACHLYS.profile:291:## - spawnto can only be 63 chars
ACHLYS.profile:292:## - OPSEC WARNING!!!! The spawnto in this example will contain identifiable command line strings
ACHLYS.profile:303:## - set spawnto_x86 "%windir%\\syswow64\\svchost.exe -k netsvcs";
ACHLYS.profile:304:## - set spawnto_x64 "%windir%\\sysnative\\svchost.exe -k netsvcs";
ACHLYS.profile:312: set spawnto_x86 "%windir%\\syswow64\\dllhost.exe";
ACHLYS.profile:314: set spawnto_x64 "%windir%\\sysnative\\dllhost.exe";
amazon.profile:175: #set spawnto_x86 "%windir%\\syswow64\\gpresult.exe";
amazon.profile:176: #set spawnto_x64 "%windir%\\sysnative\\gpresult.exe";
amazon.profile:178: #set spawnto_x86 "%windir%\\syswow64\\svchost.exe -k netsvcs";
amazon.profile:179: #set spawnto_x64 "%windir%\\sysnative\\svchost.exe -k netsvcs";
amazon.profile:181: set spawnto_x86 "%windir%\\syswow64\\FlashPlayerApp.exe";
amazon.profile:182: set spawnto_x64 "C:\\Program Files (x86)\\Google\\Chrome\\Application\\chrome.exe";
amazon.profile:184: #set spawnto_x86 "C:\\Program Files (x86)\\Microsoft Office\\Office16\\excelcnv.exe";
amazon.profile:185: #set spawnto_x64 "C:\\Program Files\\Mozilla Firefox\\firefox.exe";
amazon2.profile:85: set spawnto_x86 "%windir%\\syswow64\\svchost.exe -k netsvcs";
amazon2.profile:86: set spawnto_x64 "C:\\Program Files (x86)\\Google\\Chrome\\Application\\chrome.exe";
bcbb5cb2.profile:169: set spawnto_x86 "%windir%\\syswow64\\WUAUCLT.exe";
bcbb5cb2.profile:170: set spawnto_x64 "%windir%\\sysnative\\WUAUCLT.exe";
c3a22d29.profile:178: set spawnto_x86 "%windir%\\syswow64\\WUAUCLT.exe";
c3a22d29.profile:179: set spawnto_x64 "%windir%\\sysnative\\WUAUCLT.exe";
chches_APT10.profile:133:set spawnto_x86 "%windir%\\syswow64\\reg.exe";
chches_APT10.profile:134:set spawnto_x64 "%windir%\\sysnative\\reg.exe";
clean_template.profile:369: set spawnto_x86 "%windir%\\syswow64\\gpupdate.exe";
clean_template.profile:370: set spawnto_x64 "%windir%\\sysnative\\gpupdate.exe";
cnd.profile:117:## spawnto_x86: %windir%\\syswow64\\rundll32.exe
cnd.profile:118:## spawnto_x64: %windir%\\sysnative\\rundll32.exe
cnd.profile:123:## - spawnto can only be 63 chars
cnd.profile:124:## - OPSEC WARNING!!!! The spawnto in this example will contain identifiable command line strings
cnd.profile:135:## - set spawnto_x86 "%windir%\\syswow64\\svchost.exe -k netsvcs";
cnd.profile:136:## - set spawnto_x64 "%windir%\\sysnative\\svchost.exe -k netsvcs";
cnd.profile:144: set spawnto_x86 "%windir%\\syswow64\\rundll32.exe";
cnd.profile:146: set spawnto_x64 "%windir%\\sysnative\\rundll32.exe";
cobalt.profile:117:## spawnto_x86: %windir%\syswow64\rundll32.exe
cobalt.profile:118:## spawnto_x64: %windir%\sysnative\rundll32.exe
cobalt.profile:120:## - OPSEC WARNING!!!! The spawnto in this example will contain identifiable command line strings
cobalt.profile:130:set spawnto_x86 "%windir%\\syswow64\\svchost.exe -k netsvcs";
cobalt.profile:131:set spawnto_x64 "%windir%\\sysnative\\svchost.exe -k netsvcs";
covid19_koadic.profile:353: set spawnto_x86 "%windir%\\syswow64\\rundll32.exe";
covid19_koadic.profile:354: set spawnto_x64 "%windir%\\sysnative\\rundll32.exe";
CS4.0_guideline.profile:311: set spawnto_x86 "%windir%\\syswow64\\<mfpmp>.exe"; # Do not specify %windir%\system32 or c:\windows\system32 direc
CS4.0_guideline.profile:312: set spawnto_x64 "%windir%\\sysnative\\<mfpmp>.exe"; # Do not specify %windir%\system32 or c:\windows\system32 direc
duckduckgo-ramen-search-get-only.profile:13:set spawnto_x86 "%windir%\\syswow64\\gpresult.exe";
duckduckgo-ramen-search-get-only.profile:14:set spawnto_x64 "%windir%\\sysnative\\gpupdate.exe";
dukes_apt29.profile:295: set spawnto_x86 "%windir%\\syswow64\\dllhost.exe";
dukes_apt29.profile:296: set spawnto_x64 "%windir%\\sysnative\\dllhost.exe";
evasive.profile:176: set spawnto_x86 "%windir%\\syswow64\\WUAUCLT.exe";
evasive.profile:177: set spawnto_x64 "%windir%\\sysnative\\WUAUCLT.exe";
ex.profile:192: set spawnto_x86 "%windir%\\syswow64\\explorer.exe";
ex.profile:193: set spawnto_x64 "%windir%\\explorer.exe";
example.profile:83: set spawnto_x86 "%windir%\\syswow64\\notepad.exe";
example.profile:84: set spawnto_x64 "%windir%\\sysnative\\notepad.exe";
gmail.profile:17:set spawnto "userinit.exe";
gotomeeting.profile:170:#always test spawnto and module stomp before using. My examples tested on Windows 10 Pro.
gotomeeting.profile:174: set spawnto_x86 "%windir%\\syswow64\\gpupdate.exe";
gotomeeting.profile:175: set spawnto_x64 "%windir%\\sysnative\\gpupdate.exe";
iheartradio.profile:212: set spawnto_x86 "%windir%\\syswow64\\gpupdate.exe";
iheartradio.profile:213: set spawnto_x64 "%windir%\\sysnative\\gpupdate.exe";
jasperloader.profile:163: set spawnto_x86 "%windir%\\syswow64\\wscript.exe";
jasperloader.profile:164: set spawnto_x64 "%windir%\\sysnative\\wscript.exe";
jquery-c2.3.11.profile:116:## spawnto_x86: %windir%\syswow64\rundll32.exe
jquery-c2.3.11.profile:117:## spawnto_x64: %windir%\sysnative\rundll32.exe
jquery-c2.3.11.profile:119:## - OPSEC WARNING!!!! The spawnto in this example will contain identifiable command line strings
jquery-c2.3.11.profile:129:set spawnto_x86 "%windir%\\syswow64\\svchost.exe -k netsvcs";
jquery-c2.3.11.profile:130:set spawnto_x64 "%windir%\\sysnative\\svchost.exe -k netsvcs";
jquery-c2.3.12.profile:116:## spawnto_x86: %windir%\syswow64\rundll32.exe
jquery-c2.3.12.profile:117:## spawnto_x64: %windir%\sysnative\rundll32.exe
jquery-c2.3.12.profile:119:## - OPSEC WARNING!!!! The spawnto in this example will contain identifiable command line strings
jquery-c2.3.12.profile:129:set spawnto_x86 "%windir%\\syswow64\\svchost.exe -k netsvcs";
jquery-c2.3.12.profile:130:set spawnto_x64 "%windir%\\sysnative\\svchost.exe -k netsvcs";
jquery-c2.3.13.profile:133:## spawnto_x86: %windir%\syswow64\rundll32.exe
jquery-c2.3.13.profile:134:## spawnto_x64: %windir%\sysnative\rundll32.exe
jquery-c2.3.13.profile:136:## - spawnto can only be 63 chars
jquery-c2.3.13.profile:137:## - OPSEC WARNING!!!! The spawnto in this example will contain identifiable command line strings
jquery-c2.3.13.profile:147:set spawnto_x86 "%windir%\\syswow64\\svchost.exe -k netsvcs";
jquery-c2.3.13.profile:148:set spawnto_x64 "%windir%\\sysnative\\svchost.exe -k netsvcs";
jquery-c2.3.14.profile:131:## spawnto_x86: %windir%\syswow64\rundll32.exe
jquery-c2.3.14.profile:132:## spawnto_x64: %windir%\sysnative\rundll32.exe
jquery-c2.3.14.profile:134:## - spawnto can only be 63 chars
jquery-c2.3.14.profile:135:## - OPSEC WARNING!!!! The spawnto in this example will contain identifiable command line strings
jquery-c2.3.14.profile:146:## - set spawnto_x86 "%windir%\\syswow64\\svchost.exe -k netsvcs";
jquery-c2.3.14.profile:147:## - set spawnto_x64 "%windir%\\sysnative\\svchost.exe -k netsvcs";
jquery-c2.3.14.profile:152: set spawnto_x86 "%windir%\\syswow64\\dllhost.exe";
jquery-c2.3.14.profile:153: set spawnto_x64 "%windir%\\sysnative\\dllhost.exe";
jquery-c2.4.0.profile:117:## spawnto_x86: %windir%\\syswow64\\rundll32.exe
jquery-c2.4.0.profile:118:## spawnto_x64: %windir%\\sysnative\\rundll32.exe
jquery-c2.4.0.profile:123:## - spawnto can only be 63 chars
jquery-c2.4.0.profile:124:## - OPSEC WARNING!!!! The spawnto in this example will contain identifiable command line strings
jquery-c2.4.0.profile:135:## - set spawnto_x86 "%windir%\\syswow64\\svchost.exe -k netsvcs";
jquery-c2.4.0.profile:136:## - set spawnto_x64 "%windir%\\sysnative\\svchost.exe -k netsvcs";
jquery-c2.4.0.profile:144: set spawnto_x86 "%windir%\\syswow64\\dllhost.exe";
jquery-c2.4.0.profile:146: set spawnto_x64 "%windir%\\sysnative\\dllhost.exe";
jquery-c2.4.2.profile:257:## spawnto_x86 %windir%\\syswow64\\rundll32.exe
jquery-c2.4.2.profile:258:## spawnto_x64 %windir%\\sysnative\\rundll32.exe
jquery-c2.4.2.profile:266:## - spawnto can only be 63 chars
jquery-c2.4.2.profile:267:## - OPSEC WARNING!!!! The spawnto in this example will contain identifiable command line strings
jquery-c2.4.2.profile:278:## - set spawnto_x86 "%windir%\\syswow64\\svchost.exe -k netsvcs";
jquery-c2.4.2.profile:279:## - set spawnto_x64 "%windir%\\sysnative\\svchost.exe -k netsvcs";
jquery-c2.4.2.profile:287: set spawnto_x86 "%windir%\\syswow64\\dllhost.exe";
jquery-c2.4.2.profile:289: set spawnto_x64 "%windir%\\sysnative\\dllhost.exe";
jquery-c2.4.3.profile:282:## spawnto_x86 %windir%\\syswow64\\rundll32.exe
jquery-c2.4.3.profile:283:## spawnto_x64 %windir%\\sysnative\\rundll32.exe
jquery-c2.4.3.profile:291:## - spawnto can only be 63 chars
jquery-c2.4.3.profile:292:## - OPSEC WARNING!!!! The spawnto in this example will contain identifiable command line strings
jquery-c2.4.3.profile:303:## - set spawnto_x86 "%windir%\\syswow64\\svchost.exe -k netsvcs";
jquery-c2.4.3.profile:304:## - set spawnto_x64 "%windir%\\sysnative\\svchost.exe -k netsvcs";
jquery-c2.4.3.profile:312: set spawnto_x86 "%windir%\\syswow64\\dllhost.exe";
jquery-c2.4.3.profile:314: set spawnto_x64 "%windir%\\sysnative\\dllhost.exe";
lee-malleable-skeleton.profile:16:set spawnto_x86 "%windir%\\syswow64\\calc.exe";
lee-malleable-skeleton.profile:17:set spawnto_x64 "%windir%\\sysnative\\notepad.exe";
mayoclinic.profile:144:#always test spawnto and module stomp before using. My examples tested on Windows 10 Pro.
mayoclinic.profile:148: set spawnto_x86 "%windir%\\syswow64\\gpupdate.exe";
mayoclinic.profile:149: set spawnto_x64 "%windir%\\sysnative\\gpupdate.exe";
meterpreter.profile:13:set spawnto_x86 "%windir%\\syswow64\\notepad.exe";
meterpreter.profile:14:set spawnto_x64 "%windir%\\sysnative\\notepad.exe";
mscrl.profile:359: set spawnto_x86 "%windir%\\syswow64\\gpupdate.exe";
mscrl.profile:360: set spawnto_x64 "%windir%\\sysnative\\gpupdate.exe";
msu_edu.profile:333: set spawnto_x86 "%windir%\\syswow64\\gpupdate.exe";
msu_edu.profile:334: set spawnto_x64 "%windir%\\sysnative\\gpupdate.exe";
myhttpsc2.profile:501: set spawnto_x86 "%windir%\\syswow64\\gpupdate.exe";
myhttpsc2.profile:502: set spawnto_x64 "%windir%\\sysnative\\gpupdate.exe";
office365_calendar.profile:158: set spawnto_x86 "%windir%\\syswow64\\gpupdate.exe";
office365_calendar.profile:159: set spawnto_x64 "%windir%\\sysnative\\gpupdate.exe";
rawsss.profile:88: set spawnto_x86 "%windir%\\syswow64\\msvpdate.exe";
rawsss.profile:89: set spawnto_x64 "%windir%\\sysnative\\msvpdate.exe";
reddit.profile:149: set spawnto_x86 "%windir%\\syswow64\\gpupdate.exe";
reddit.profile:150: set spawnto_x64 "%windir%\\sysnative\\gpupdate.exe";
reference.profile:308: set spawnto_x86 "%windir%\\syswow64\\WerFault.exe";
reference.profile:309: set spawnto_x64 "%windir%\\sysnative\\WerFault.exe";
saefko.profile:154: set spawnto_x86 "%windir%\\syswow64\\wscript.exe";
saefko.profile:155: set spawnto_x64 "%windir%\\sysnative\\wscript.exe";
salesforce_api.profile:325: set spawnto_x86 "%windir%\\syswow64\\gpupdate.exe";
salesforce_api.profile:326: set spawnto_x64 "%windir%\\sysnative\\gpupdate.exe";
slack.profile:211: set spawnto_x86 "%windir%\\syswow64\\gpupdate.exe";
slack.profile:212: set spawnto_x64 "%windir%\\sysnative\\gpupdate.exe";
stackoverflow.profile:192:#always test spawnto and module stomp before using. My examples tested on Windows 10 Pro.
stackoverflow.profile:196: set spawnto_x86 "%windir%\\syswow64\\gpupdate.exe";
stackoverflow.profile:197: set spawnto_x64 "%windir%\\sysnative\\gpupdate.exe";
template.profile:547: set spawnto_x86 "%windir%\\syswow64\\gpupdate.exe";
template.profile:548: set spawnto_x64 "%windir%\\sysnative\\gpupdate.exe";
trevor.profile:165: set spawnto_x86 "%windir%\\syswow64\\gpupdate.exe";
trevor.profile:166: set spawnto_x64 "%windir%\\sysnative\\gpupdate.exe";
trick_ryuk.profile:380: set spawnto_x86 "%windir%\\syswow64\\gpupdate.exe";
trick_ryuk.profile:381: set spawnto_x64 "%windir%\\sysnative\\gpupdate.exe";
windows-updates.profile:72: set spawnto_x86 "%windir%\\syswow64\\wusa.exe";
windows-updates.profile:75: set spawnto_x64 "%windir%\\sysnative\\wusa.exe";
youtube_video.profile:177: set spawnto_x86 "%windir%\\syswow64\\gpupdate.exe";
youtube_video.profile:178: set spawnto_x64 "%windir%\\sysnative\\gpupdate.exe";
zillow.profile:172: set spawnto_x86 "%windir%\\syswow64\\gpresult.exe";
zillow.profile:173: set spawnto_x64 "%windir%\\sysnative\\gpresult.exe";
zloader.profile:367: set spawnto_x86 "%windir%\\syswow64\\explorer.exe";
zloader.profile:368: set spawnto_x64 "%windir%\\sysnative\\explorer.exe";
zoom.profile:347: set spawnto_x86 "%windir%\\syswow64\\gpupdate.exe";
zoom.profile:348: set spawnto_x64 "%windir%\\sysnative\\gpupdate.exe";
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment