Created
September 28, 2021 21:15
-
-
Save MHaggis/dc1f1c2ebbe884bb27065479321b06b8 to your computer and use it in GitHub Desktop.
Identified SpawnTo from https://gist.github.com/MHaggis/921a4a47de1adab7eec938b4597f0be3
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
17ae38f1.profile:177: set spawnto_x86 "%windir%\\syswow64\\regsvr32.exe"; | |
17ae38f1.profile:178: set spawnto_x64 "%windir%\\sysnative\\regsvr32.exe"; | |
5d93e051.profile:167: set spawnto_x86 "%windir%\\syswow64\\regsvr32.exe"; | |
5d93e051.profile:168: set spawnto_x64 "%windir%\\sysnative\\regsvr32.exe"; | |
ACHLYS.profile:282:## spawnto_x86 %windir%\\syswow64\\rundll32.exe | |
ACHLYS.profile:283:## spawnto_x64 %windir%\\sysnative\\rundll32.exe | |
ACHLYS.profile:291:## - spawnto can only be 63 chars | |
ACHLYS.profile:292:## - OPSEC WARNING!!!! The spawnto in this example will contain identifiable command line strings | |
ACHLYS.profile:303:## - set spawnto_x86 "%windir%\\syswow64\\svchost.exe -k netsvcs"; | |
ACHLYS.profile:304:## - set spawnto_x64 "%windir%\\sysnative\\svchost.exe -k netsvcs"; | |
ACHLYS.profile:312: set spawnto_x86 "%windir%\\syswow64\\dllhost.exe"; | |
ACHLYS.profile:314: set spawnto_x64 "%windir%\\sysnative\\dllhost.exe"; | |
amazon.profile:175: #set spawnto_x86 "%windir%\\syswow64\\gpresult.exe"; | |
amazon.profile:176: #set spawnto_x64 "%windir%\\sysnative\\gpresult.exe"; | |
amazon.profile:178: #set spawnto_x86 "%windir%\\syswow64\\svchost.exe -k netsvcs"; | |
amazon.profile:179: #set spawnto_x64 "%windir%\\sysnative\\svchost.exe -k netsvcs"; | |
amazon.profile:181: set spawnto_x86 "%windir%\\syswow64\\FlashPlayerApp.exe"; | |
amazon.profile:182: set spawnto_x64 "C:\\Program Files (x86)\\Google\\Chrome\\Application\\chrome.exe"; | |
amazon.profile:184: #set spawnto_x86 "C:\\Program Files (x86)\\Microsoft Office\\Office16\\excelcnv.exe"; | |
amazon.profile:185: #set spawnto_x64 "C:\\Program Files\\Mozilla Firefox\\firefox.exe"; | |
amazon2.profile:85: set spawnto_x86 "%windir%\\syswow64\\svchost.exe -k netsvcs"; | |
amazon2.profile:86: set spawnto_x64 "C:\\Program Files (x86)\\Google\\Chrome\\Application\\chrome.exe"; | |
bcbb5cb2.profile:169: set spawnto_x86 "%windir%\\syswow64\\WUAUCLT.exe"; | |
bcbb5cb2.profile:170: set spawnto_x64 "%windir%\\sysnative\\WUAUCLT.exe"; | |
c3a22d29.profile:178: set spawnto_x86 "%windir%\\syswow64\\WUAUCLT.exe"; | |
c3a22d29.profile:179: set spawnto_x64 "%windir%\\sysnative\\WUAUCLT.exe"; | |
chches_APT10.profile:133:set spawnto_x86 "%windir%\\syswow64\\reg.exe"; | |
chches_APT10.profile:134:set spawnto_x64 "%windir%\\sysnative\\reg.exe"; | |
clean_template.profile:369: set spawnto_x86 "%windir%\\syswow64\\gpupdate.exe"; | |
clean_template.profile:370: set spawnto_x64 "%windir%\\sysnative\\gpupdate.exe"; | |
cnd.profile:117:## spawnto_x86: %windir%\\syswow64\\rundll32.exe | |
cnd.profile:118:## spawnto_x64: %windir%\\sysnative\\rundll32.exe | |
cnd.profile:123:## - spawnto can only be 63 chars | |
cnd.profile:124:## - OPSEC WARNING!!!! The spawnto in this example will contain identifiable command line strings | |
cnd.profile:135:## - set spawnto_x86 "%windir%\\syswow64\\svchost.exe -k netsvcs"; | |
cnd.profile:136:## - set spawnto_x64 "%windir%\\sysnative\\svchost.exe -k netsvcs"; | |
cnd.profile:144: set spawnto_x86 "%windir%\\syswow64\\rundll32.exe"; | |
cnd.profile:146: set spawnto_x64 "%windir%\\sysnative\\rundll32.exe"; | |
cobalt.profile:117:## spawnto_x86: %windir%\syswow64\rundll32.exe | |
cobalt.profile:118:## spawnto_x64: %windir%\sysnative\rundll32.exe | |
cobalt.profile:120:## - OPSEC WARNING!!!! The spawnto in this example will contain identifiable command line strings | |
cobalt.profile:130:set spawnto_x86 "%windir%\\syswow64\\svchost.exe -k netsvcs"; | |
cobalt.profile:131:set spawnto_x64 "%windir%\\sysnative\\svchost.exe -k netsvcs"; | |
covid19_koadic.profile:353: set spawnto_x86 "%windir%\\syswow64\\rundll32.exe"; | |
covid19_koadic.profile:354: set spawnto_x64 "%windir%\\sysnative\\rundll32.exe"; | |
CS4.0_guideline.profile:311: set spawnto_x86 "%windir%\\syswow64\\<mfpmp>.exe"; # Do not specify %windir%\system32 or c:\windows\system32 direc | |
CS4.0_guideline.profile:312: set spawnto_x64 "%windir%\\sysnative\\<mfpmp>.exe"; # Do not specify %windir%\system32 or c:\windows\system32 direc | |
duckduckgo-ramen-search-get-only.profile:13:set spawnto_x86 "%windir%\\syswow64\\gpresult.exe"; | |
duckduckgo-ramen-search-get-only.profile:14:set spawnto_x64 "%windir%\\sysnative\\gpupdate.exe"; | |
dukes_apt29.profile:295: set spawnto_x86 "%windir%\\syswow64\\dllhost.exe"; | |
dukes_apt29.profile:296: set spawnto_x64 "%windir%\\sysnative\\dllhost.exe"; | |
evasive.profile:176: set spawnto_x86 "%windir%\\syswow64\\WUAUCLT.exe"; | |
evasive.profile:177: set spawnto_x64 "%windir%\\sysnative\\WUAUCLT.exe"; | |
ex.profile:192: set spawnto_x86 "%windir%\\syswow64\\explorer.exe"; | |
ex.profile:193: set spawnto_x64 "%windir%\\explorer.exe"; | |
example.profile:83: set spawnto_x86 "%windir%\\syswow64\\notepad.exe"; | |
example.profile:84: set spawnto_x64 "%windir%\\sysnative\\notepad.exe"; | |
gmail.profile:17:set spawnto "userinit.exe"; | |
gotomeeting.profile:170:#always test spawnto and module stomp before using. My examples tested on Windows 10 Pro. | |
gotomeeting.profile:174: set spawnto_x86 "%windir%\\syswow64\\gpupdate.exe"; | |
gotomeeting.profile:175: set spawnto_x64 "%windir%\\sysnative\\gpupdate.exe"; | |
iheartradio.profile:212: set spawnto_x86 "%windir%\\syswow64\\gpupdate.exe"; | |
iheartradio.profile:213: set spawnto_x64 "%windir%\\sysnative\\gpupdate.exe"; | |
jasperloader.profile:163: set spawnto_x86 "%windir%\\syswow64\\wscript.exe"; | |
jasperloader.profile:164: set spawnto_x64 "%windir%\\sysnative\\wscript.exe"; | |
jquery-c2.3.11.profile:116:## spawnto_x86: %windir%\syswow64\rundll32.exe | |
jquery-c2.3.11.profile:117:## spawnto_x64: %windir%\sysnative\rundll32.exe | |
jquery-c2.3.11.profile:119:## - OPSEC WARNING!!!! The spawnto in this example will contain identifiable command line strings | |
jquery-c2.3.11.profile:129:set spawnto_x86 "%windir%\\syswow64\\svchost.exe -k netsvcs"; | |
jquery-c2.3.11.profile:130:set spawnto_x64 "%windir%\\sysnative\\svchost.exe -k netsvcs"; | |
jquery-c2.3.12.profile:116:## spawnto_x86: %windir%\syswow64\rundll32.exe | |
jquery-c2.3.12.profile:117:## spawnto_x64: %windir%\sysnative\rundll32.exe | |
jquery-c2.3.12.profile:119:## - OPSEC WARNING!!!! The spawnto in this example will contain identifiable command line strings | |
jquery-c2.3.12.profile:129:set spawnto_x86 "%windir%\\syswow64\\svchost.exe -k netsvcs"; | |
jquery-c2.3.12.profile:130:set spawnto_x64 "%windir%\\sysnative\\svchost.exe -k netsvcs"; | |
jquery-c2.3.13.profile:133:## spawnto_x86: %windir%\syswow64\rundll32.exe | |
jquery-c2.3.13.profile:134:## spawnto_x64: %windir%\sysnative\rundll32.exe | |
jquery-c2.3.13.profile:136:## - spawnto can only be 63 chars | |
jquery-c2.3.13.profile:137:## - OPSEC WARNING!!!! The spawnto in this example will contain identifiable command line strings | |
jquery-c2.3.13.profile:147:set spawnto_x86 "%windir%\\syswow64\\svchost.exe -k netsvcs"; | |
jquery-c2.3.13.profile:148:set spawnto_x64 "%windir%\\sysnative\\svchost.exe -k netsvcs"; | |
jquery-c2.3.14.profile:131:## spawnto_x86: %windir%\syswow64\rundll32.exe | |
jquery-c2.3.14.profile:132:## spawnto_x64: %windir%\sysnative\rundll32.exe | |
jquery-c2.3.14.profile:134:## - spawnto can only be 63 chars | |
jquery-c2.3.14.profile:135:## - OPSEC WARNING!!!! The spawnto in this example will contain identifiable command line strings | |
jquery-c2.3.14.profile:146:## - set spawnto_x86 "%windir%\\syswow64\\svchost.exe -k netsvcs"; | |
jquery-c2.3.14.profile:147:## - set spawnto_x64 "%windir%\\sysnative\\svchost.exe -k netsvcs"; | |
jquery-c2.3.14.profile:152: set spawnto_x86 "%windir%\\syswow64\\dllhost.exe"; | |
jquery-c2.3.14.profile:153: set spawnto_x64 "%windir%\\sysnative\\dllhost.exe"; | |
jquery-c2.4.0.profile:117:## spawnto_x86: %windir%\\syswow64\\rundll32.exe | |
jquery-c2.4.0.profile:118:## spawnto_x64: %windir%\\sysnative\\rundll32.exe | |
jquery-c2.4.0.profile:123:## - spawnto can only be 63 chars | |
jquery-c2.4.0.profile:124:## - OPSEC WARNING!!!! The spawnto in this example will contain identifiable command line strings | |
jquery-c2.4.0.profile:135:## - set spawnto_x86 "%windir%\\syswow64\\svchost.exe -k netsvcs"; | |
jquery-c2.4.0.profile:136:## - set spawnto_x64 "%windir%\\sysnative\\svchost.exe -k netsvcs"; | |
jquery-c2.4.0.profile:144: set spawnto_x86 "%windir%\\syswow64\\dllhost.exe"; | |
jquery-c2.4.0.profile:146: set spawnto_x64 "%windir%\\sysnative\\dllhost.exe"; | |
jquery-c2.4.2.profile:257:## spawnto_x86 %windir%\\syswow64\\rundll32.exe | |
jquery-c2.4.2.profile:258:## spawnto_x64 %windir%\\sysnative\\rundll32.exe | |
jquery-c2.4.2.profile:266:## - spawnto can only be 63 chars | |
jquery-c2.4.2.profile:267:## - OPSEC WARNING!!!! The spawnto in this example will contain identifiable command line strings | |
jquery-c2.4.2.profile:278:## - set spawnto_x86 "%windir%\\syswow64\\svchost.exe -k netsvcs"; | |
jquery-c2.4.2.profile:279:## - set spawnto_x64 "%windir%\\sysnative\\svchost.exe -k netsvcs"; | |
jquery-c2.4.2.profile:287: set spawnto_x86 "%windir%\\syswow64\\dllhost.exe"; | |
jquery-c2.4.2.profile:289: set spawnto_x64 "%windir%\\sysnative\\dllhost.exe"; | |
jquery-c2.4.3.profile:282:## spawnto_x86 %windir%\\syswow64\\rundll32.exe | |
jquery-c2.4.3.profile:283:## spawnto_x64 %windir%\\sysnative\\rundll32.exe | |
jquery-c2.4.3.profile:291:## - spawnto can only be 63 chars | |
jquery-c2.4.3.profile:292:## - OPSEC WARNING!!!! The spawnto in this example will contain identifiable command line strings | |
jquery-c2.4.3.profile:303:## - set spawnto_x86 "%windir%\\syswow64\\svchost.exe -k netsvcs"; | |
jquery-c2.4.3.profile:304:## - set spawnto_x64 "%windir%\\sysnative\\svchost.exe -k netsvcs"; | |
jquery-c2.4.3.profile:312: set spawnto_x86 "%windir%\\syswow64\\dllhost.exe"; | |
jquery-c2.4.3.profile:314: set spawnto_x64 "%windir%\\sysnative\\dllhost.exe"; | |
lee-malleable-skeleton.profile:16:set spawnto_x86 "%windir%\\syswow64\\calc.exe"; | |
lee-malleable-skeleton.profile:17:set spawnto_x64 "%windir%\\sysnative\\notepad.exe"; | |
mayoclinic.profile:144:#always test spawnto and module stomp before using. My examples tested on Windows 10 Pro. | |
mayoclinic.profile:148: set spawnto_x86 "%windir%\\syswow64\\gpupdate.exe"; | |
mayoclinic.profile:149: set spawnto_x64 "%windir%\\sysnative\\gpupdate.exe"; | |
meterpreter.profile:13:set spawnto_x86 "%windir%\\syswow64\\notepad.exe"; | |
meterpreter.profile:14:set spawnto_x64 "%windir%\\sysnative\\notepad.exe"; | |
mscrl.profile:359: set spawnto_x86 "%windir%\\syswow64\\gpupdate.exe"; | |
mscrl.profile:360: set spawnto_x64 "%windir%\\sysnative\\gpupdate.exe"; | |
msu_edu.profile:333: set spawnto_x86 "%windir%\\syswow64\\gpupdate.exe"; | |
msu_edu.profile:334: set spawnto_x64 "%windir%\\sysnative\\gpupdate.exe"; | |
myhttpsc2.profile:501: set spawnto_x86 "%windir%\\syswow64\\gpupdate.exe"; | |
myhttpsc2.profile:502: set spawnto_x64 "%windir%\\sysnative\\gpupdate.exe"; | |
office365_calendar.profile:158: set spawnto_x86 "%windir%\\syswow64\\gpupdate.exe"; | |
office365_calendar.profile:159: set spawnto_x64 "%windir%\\sysnative\\gpupdate.exe"; | |
rawsss.profile:88: set spawnto_x86 "%windir%\\syswow64\\msvpdate.exe"; | |
rawsss.profile:89: set spawnto_x64 "%windir%\\sysnative\\msvpdate.exe"; | |
reddit.profile:149: set spawnto_x86 "%windir%\\syswow64\\gpupdate.exe"; | |
reddit.profile:150: set spawnto_x64 "%windir%\\sysnative\\gpupdate.exe"; | |
reference.profile:308: set spawnto_x86 "%windir%\\syswow64\\WerFault.exe"; | |
reference.profile:309: set spawnto_x64 "%windir%\\sysnative\\WerFault.exe"; | |
saefko.profile:154: set spawnto_x86 "%windir%\\syswow64\\wscript.exe"; | |
saefko.profile:155: set spawnto_x64 "%windir%\\sysnative\\wscript.exe"; | |
salesforce_api.profile:325: set spawnto_x86 "%windir%\\syswow64\\gpupdate.exe"; | |
salesforce_api.profile:326: set spawnto_x64 "%windir%\\sysnative\\gpupdate.exe"; | |
slack.profile:211: set spawnto_x86 "%windir%\\syswow64\\gpupdate.exe"; | |
slack.profile:212: set spawnto_x64 "%windir%\\sysnative\\gpupdate.exe"; | |
stackoverflow.profile:192:#always test spawnto and module stomp before using. My examples tested on Windows 10 Pro. | |
stackoverflow.profile:196: set spawnto_x86 "%windir%\\syswow64\\gpupdate.exe"; | |
stackoverflow.profile:197: set spawnto_x64 "%windir%\\sysnative\\gpupdate.exe"; | |
template.profile:547: set spawnto_x86 "%windir%\\syswow64\\gpupdate.exe"; | |
template.profile:548: set spawnto_x64 "%windir%\\sysnative\\gpupdate.exe"; | |
trevor.profile:165: set spawnto_x86 "%windir%\\syswow64\\gpupdate.exe"; | |
trevor.profile:166: set spawnto_x64 "%windir%\\sysnative\\gpupdate.exe"; | |
trick_ryuk.profile:380: set spawnto_x86 "%windir%\\syswow64\\gpupdate.exe"; | |
trick_ryuk.profile:381: set spawnto_x64 "%windir%\\sysnative\\gpupdate.exe"; | |
windows-updates.profile:72: set spawnto_x86 "%windir%\\syswow64\\wusa.exe"; | |
windows-updates.profile:75: set spawnto_x64 "%windir%\\sysnative\\wusa.exe"; | |
youtube_video.profile:177: set spawnto_x86 "%windir%\\syswow64\\gpupdate.exe"; | |
youtube_video.profile:178: set spawnto_x64 "%windir%\\sysnative\\gpupdate.exe"; | |
zillow.profile:172: set spawnto_x86 "%windir%\\syswow64\\gpresult.exe"; | |
zillow.profile:173: set spawnto_x64 "%windir%\\sysnative\\gpresult.exe"; | |
zloader.profile:367: set spawnto_x86 "%windir%\\syswow64\\explorer.exe"; | |
zloader.profile:368: set spawnto_x64 "%windir%\\sysnative\\explorer.exe"; | |
zoom.profile:347: set spawnto_x86 "%windir%\\syswow64\\gpupdate.exe"; | |
zoom.profile:348: set spawnto_x64 "%windir%\\sysnative\\gpupdate.exe"; |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment