indicatorfilename
svchost32.exe
- First seen
- 2026-05-22
- Last seen
- 2026-05-22
- Sightings
- 1
Posts referencing this indicator
- The Gentlemen (Ransomware) in Disguise: Defense Evasion and other TTPs
Malicious binary disguised as a system process to create a SOCKS proxy C2 connection.