The typographical and homomorphic abuse of svchost.exe

July 4, 2013 in Batch Analysis, Malware Analysis, Silly

Update

I have re-visited this topic here.

Old post

Probably the most abused file name in the history of a mankind is svchost.exe. The number of its look-alike variations created by the perverse mind and deprived imagination of malware authors is staggering.

The following list is a testament to… oh, whatever…  it’s just a few examples extracted from a list of IOCs 🙂

  • svchost
  • svch0st
  • svchosts
  • scvhost
  • svhost
  • svohost
  • svchest
  • svchost32
  • suchost
  • svshost
  • svchast
  • svcnost
  • syshost
  • svchcst
  • svchost
  • svchon32
  • svchost2
  • svcchost
  • sxhost
  • svchost31
  • syschost
  • svchîst
  • synchost
  • svchpst
  • svohcst
  • svghost
  • svchostms
  • svchostxxx
  • suchostp
  • suchosts
  • smsvchost
  • svcehost
  • svphost
  • svchostdll
  • svvhosti
  • sach0st
  • swchost
  • servehost
  • svsh0st
  • svchsot
  • scchostc
  • snvhost
  • scchost
  • svvhost
  • svahost
  • svcinit
  • ssvch0st
  • svchots
  • svdhost
  • svchostv
  • scvchusts
  • svchostxi
  • st#host
  • svchost3
  • scanost
  • schosts
  • svchost0
  • svchost64
  • svchöst
  • s_host
  • svchost”
  • svphostu
  • svchostc32
  • szchostc
  • svehost
  • srvchost
  • svchosts32
  • scvhosv
  • ssvichosst
  • svrhost
  • svichosst
  • svchoxt
  • svchost_cz
  • schost
  • ssvchost
  • sv±hest
  • shhost
  • svchostt
  • svchosf
  • svchostþ
  • sachostp
  • sachosts
  • sachostx
  • swhost
  • scvh0st
  • svcroot
  • svschost
  • svchosting
  • sachostc
  • sachostw
  • svshoct

 

Share this :)

Comments are closed.