{"id":3430,"date":"2015-12-18T16:57:40","date_gmt":"2015-12-18T16:57:40","guid":{"rendered":"http:\/\/www.hexacorn.com\/blog\/?p=3430"},"modified":"2015-12-18T16:59:49","modified_gmt":"2015-12-18T16:59:49","slug":"the-typographical-and-homomorphic-abuse-of-svchost-exe-and-other-popular-file-names","status":"publish","type":"post","link":"https:\/\/www.hexacorn.com\/blog\/2015\/12\/18\/the-typographical-and-homomorphic-abuse-of-svchost-exe-and-other-popular-file-names\/","title":{"rendered":"The typographical and homomorphic abuse of svchost.exe, and other popular file names"},"content":{"rendered":"<p>In my <a href=\"https:\/\/www.hexacorn.com\/blog\/2013\/07\/04\/the-typographical-and-homomorphic-abuse-of-svchost-exe\/\">old post<\/a> I described a list of file names used by malware to impersonate svchost.exe. I thought I will re-visit this post today and provide some more file names that malware is using for impersonation of common file names.<\/p>\n<p><strong>Copyright Notice<\/strong><\/p>\n<p>Feel free to use it for any individual or academic projects that are non-commercial f.ex. internal automatic malware\/ forensic analysis systems that are not available commercially (f.ex. if you want to use it to write an Enscript, or perl\/python script, or Yara\/Cuckoo\/Volatility code highlighting suspicious file names based on the below blacklist you are welcome to do so; if you share the script publicly it&#8217;s even better \ud83d\ude42 ). I do not allow you to use this list in any commercial product or service including, but not limited to sandboxes &amp; automatic malware\/forensic processing systems. If you want to use it for anything that has a commercial\/reselling purposes or may give a hint of such purpose please contact me first. Please note that this list may be watermarked.<\/p>\n<p><strong>How this list was generated?<\/strong><\/p>\n<p>This is based on strings extracted from 500K sandbox reports that have been analyzed using various &#8216;similarity&#8217; functions including Levenshtein distance, prefix\/infix\/suffix similarities, and visual similarity (the final list has been reviewed manually). In other words, it costed a lot of cycles, hence the licensing note. Thanks for understanding.<\/p>\n<p>Here they are:<\/p>\n<p><strong>chrome.exe<\/strong><\/p>\n<p>5hrome<br \/>\na_chrome<br \/>\ncchrome<br \/>\nchorom<br \/>\nchr0me<br \/>\nchro2me<br \/>\nchrom<br \/>\n-chrome<br \/>\nchrome1<br \/>\nchrome10<br \/>\nchrome3<br \/>\nchrome32<br \/>\nchrome9<br \/>\nchromede<br \/>\nchromee<br \/>\nchromeez<br \/>\nchromei<br \/>\nchromes<br \/>\nchromix<br \/>\nchromme<br \/>\nchrommm<br \/>\nchromre<br \/>\nchromse<br \/>\nchromyy<br \/>\nchroom<br \/>\nchroome<br \/>\nchroum<br \/>\ncrhome<br \/>\nnichrome<\/p>\n<p><strong>csrss.exe<\/strong><\/p>\n<p>_cerss<br \/>\n_csrss<br \/>\ncarss<br \/>\nccrs<br \/>\ncress<br \/>\ncrrss<br \/>\ncrss<br \/>\ncrsss<br \/>\ncsrcs<br \/>\ncsres<br \/>\ncsriss<br \/>\ncsrlt<br \/>\ncsrms<br \/>\ncsrmss<br \/>\ncsrrss<br \/>\ncsrs<br \/>\ncsrsc<br \/>\ncsrse<br \/>\ncsrsess<br \/>\ncsrsk<br \/>\ncsrsl<br \/>\ncsrsrv<br \/>\ncsrss_1<br \/>\ncsrss_2<br \/>\ncsrss_8<br \/>\ncsrss_9<br \/>\ncsrss32<br \/>\ncsrssa<br \/>\ncsrssc<br \/>\ncsrsses<br \/>\ncsrssr<br \/>\ncsrsss<br \/>\ncsrssw<br \/>\ncsrssys<br \/>\ncsrst<br \/>\ncsrsvc<br \/>\ncsrsvr<br \/>\ncsrsx<br \/>\ncsrtss<br \/>\ncsrus<br \/>\ncsrvs<br \/>\ncssrs<br \/>\ncssrsa<br \/>\ncssrsr<br \/>\ncssrss<br \/>\ncvrss<br \/>\nscrss<\/p>\n<p><strong>explorer.exe\/iexplore.exe<\/strong><\/p>\n<p>0iexplorer<br \/>\n12iexplore<br \/>\n2ciexplore<br \/>\n2fexplorer<br \/>\n5explore<br \/>\n5xplorer<br \/>\n_iexplors<br \/>\ndexplorer<br \/>\ndxplore<br \/>\ne1xplorer<br \/>\neexplorer<br \/>\neexxplorer<br \/>\neksplorer<br \/>\nep1orer<br \/>\nesplorer<br \/>\nexeplorer<br \/>\nexlorer<br \/>\nexoplorer<br \/>\nexp10rer<br \/>\nexp1or<br \/>\nexp1ore<br \/>\nexp1orer<br \/>\nexp1ror<br \/>\nexp20re<br \/>\nexpiorer<br \/>\nexpioror<br \/>\nexpl0rer<br \/>\nexplarar<br \/>\nexplarer<br \/>\nexpleror<br \/>\nexploe<br \/>\nexploer<br \/>\nexploere<br \/>\nexploerer<br \/>\nexploiter<br \/>\nexploner<br \/>\nexplope<br \/>\nexplor<br \/>\nexplora<br \/>\nexplore<br \/>\nexplored<br \/>\nexploree<br \/>\nexploreee<br \/>\nexploreff<br \/>\nexplorei<br \/>\nexplorep<br \/>\nexplorer1<br \/>\nexplorer32<br \/>\nexplorer64<br \/>\nexplorer66<br \/>\nexplorer_<br \/>\nexplorere<br \/>\nexplorerf<br \/>\nexplorerr<br \/>\nexplorerrr<br \/>\nexplorers<br \/>\nexplorerv<br \/>\nexplorerxx<br \/>\nexplorerz<br \/>\nexplores<br \/>\nexploret<br \/>\nexplorew<br \/>\nexploror<br \/>\nexplorr<br \/>\nexplorre<br \/>\nexplorrer<br \/>\nexplorxp<br \/>\nexplre3r<br \/>\nexplrer<br \/>\nexplroer<br \/>\nexpoler<br \/>\nexpolorer<br \/>\nexporer<br \/>\nexprer<br \/>\nexprlore<br \/>\nexproler<br \/>\nexqlorer<br \/>\nexsplorer<br \/>\nexxplorer<br \/>\nieioplore<br \/>\nieplore<br \/>\nieplorer<br \/>\niexeplore<br \/>\niexlorer<br \/>\niexlplore<br \/>\niexp1ore<br \/>\niexp1orer<br \/>\niexpiore<br \/>\niexpl0ra<br \/>\niexpl0re<br \/>\niexplare<br \/>\niexplarer<br \/>\niexplere<br \/>\niexpllzore<br \/>\niexplo<br \/>\niexploer<br \/>\niexploore<br \/>\niexplope<br \/>\niexplor<br \/>\niexplore32<br \/>\niexplorea<br \/>\niexplorei<br \/>\niexplorer<br \/>\niexplorer0<br \/>\niexplorer2<br \/>\niexplorer7<br \/>\niexplorers<br \/>\niexplores<br \/>\niexploresx<br \/>\niexploror<br \/>\niexplorrer<br \/>\niexplors<br \/>\niexplory<br \/>\niexplorz<br \/>\niexpore<br \/>\niiexplore<br \/>\niiexplorer<br \/>\ninexplore<br \/>\ninexplorer<br \/>\nintexplore<br \/>\nixplorer<br \/>\nlexpiore<br \/>\nlexpl1re<br \/>\nlexpl2re<br \/>\nlexpl3re<br \/>\nlexpl4re<br \/>\nlexpl5re<br \/>\nlexpl6re<br \/>\nlexpl7re<br \/>\nlexpl8re<br \/>\nlexpl9re<br \/>\nlexplare<br \/>\nlexplbre<br \/>\nlexplcre<br \/>\nlexpldre<br \/>\nlexplere<br \/>\nlexplfre<br \/>\nlexplgre<br \/>\nlexplhre<br \/>\nlexplire<br \/>\nlexpljre<br \/>\nlexplkre<br \/>\nlexpllre<br \/>\nlexplmre<br \/>\nlexplnre<br \/>\nlexplore<br \/>\nlexplore_<br \/>\nlexplorer<br \/>\nlexplors<br \/>\nlexplpre<br \/>\nlexplqre<br \/>\nlexplrre<br \/>\nlexplsre<br \/>\nlexpltre<br \/>\nlexplure<br \/>\nlexplvre<br \/>\nlexplwre<br \/>\nlexplxre<br \/>\nlexplyre<br \/>\nlexplzre<br \/>\nmsexplorer<br \/>\nnetplore<br \/>\nplorer<br \/>\nvbexplorer<br \/>\nwexplorer<br \/>\nwinexplore<br \/>\nxeplorer<br \/>\nxplore<br \/>\nxplorer<br \/>\nyyexplorer<\/p>\n<p><strong>firefox.exe<\/strong><\/p>\n<p>5cfirefox<br \/>\n5irefox<br \/>\nf1ref0x<br \/>\nfire10fox<br \/>\nfiref0x<br \/>\nfirefly<br \/>\nfirefo<br \/>\nfirefox_<br \/>\nfirefox2<br \/>\nfirefox32<br \/>\nfirefoxe<br \/>\nfirefoxx<br \/>\nfirfox<br \/>\nirefox<br \/>\nrefox<br \/>\nwireox<\/p>\n<p><strong>java.exe<\/strong><\/p>\n<p>jav3<br \/>\njava32<br \/>\njavaa<br \/>\njavaaa<br \/>\njavaap<br \/>\njavac<br \/>\njavacp<br \/>\njavag<br \/>\njavaii<br \/>\njavapw<br \/>\njavar<br \/>\njavare<br \/>\njavas<br \/>\njavas5<br \/>\njavasc<br \/>\njavase<br \/>\njavaup<br \/>\njavavm<br \/>\njavaw<br \/>\njavaws<br \/>\njavawz<br \/>\njavax<br \/>\njavo<br \/>\njavz<\/p>\n<p><strong>lsass.exe<\/strong><\/p>\n<p>1sass<br \/>\niass<br \/>\nisaas<br \/>\nisas<br \/>\nisass<br \/>\nissass<br \/>\nlaass<br \/>\nlamss<br \/>\nlarss<br \/>\nlass<br \/>\nlassa<br \/>\nlasse<br \/>\nlasss<br \/>\nlcass<br \/>\nleass<br \/>\nlhssass<br \/>\nlrass<br \/>\nlrsss<br \/>\nlsa32<br \/>\nlsac<br \/>\nlsacs<br \/>\nlsaess<br \/>\nlsaoss<br \/>\nlsas<br \/>\nlsasa<br \/>\nlsasas<br \/>\nlsascs<br \/>\nlsase<br \/>\nlsasi<br \/>\nlsasm<br \/>\nlsaso<br \/>\nlsasrv<br \/>\nlsass3<br \/>\nlsass32<br \/>\nlsass47<br \/>\nlsassi<br \/>\nlsassn<br \/>\nlsasss<br \/>\nlsassv<br \/>\nlsassx<br \/>\nlsassys<br \/>\nlsats<br \/>\nlsmass<br \/>\nlsrss<br \/>\nlssas<br \/>\nlssass<br \/>\nmsass<br \/>\nnsrss<br \/>\nsalss<\/p>\n<p><strong>svchost.exe<\/strong><\/p>\n<p>_sachost<br \/>\n_svch0st<br \/>\n_svchost<br \/>\n00svchost<br \/>\n0svchost<br \/>\nachost<br \/>\nchost<br \/>\ncvhost<br \/>\ncvshost<br \/>\nisvchosty<br \/>\nlsvchost<br \/>\nmscchost<br \/>\nmsvchost<br \/>\nntsvchost<br \/>\nrdchost<br \/>\ns_host<br \/>\nsach0st<br \/>\nsachost<br \/>\nsachostc<br \/>\nsachostp<br \/>\nsachostp<br \/>\nsachosts<br \/>\nsachosts<br \/>\nsachostw<br \/>\nsachostw<br \/>\nsachostx<br \/>\nsathost<br \/>\nsbhost<br \/>\nscanost<br \/>\nscchost<br \/>\nscchost<br \/>\nscchost2<br \/>\nscchostc<br \/>\nscchostc<br \/>\nscghost<br \/>\nschost<br \/>\nschost<br \/>\nschostc<br \/>\nschosts<br \/>\nschovst<br \/>\nschvost<br \/>\nscvchost<br \/>\nscvchusts<br \/>\nscvh0st<br \/>\nscvh0st<br \/>\nscvhost<br \/>\nscvhost<br \/>\nscvhosv<br \/>\nscvost<br \/>\nscvvhost<br \/>\nsdchost<br \/>\nsdhost<br \/>\nserhost<br \/>\nservehost<br \/>\nsethost<br \/>\nsevchos<br \/>\nsevhost<br \/>\nshchost<br \/>\nshhost<br \/>\nshost<br \/>\nshvchost<br \/>\nshvhost<br \/>\nsichost<br \/>\nslchost<br \/>\nslihost<br \/>\nsmsvchost<br \/>\nsnahost<br \/>\nsnhost<br \/>\nsnphost<br \/>\nsnvhost<br \/>\nsochost<br \/>\nsochvst<br \/>\nsoohost<br \/>\nspchost<br \/>\nsqlhost<br \/>\nsrchost<br \/>\nsrshost<br \/>\nsrvchost<br \/>\nsrvchost<br \/>\nsrvhost<br \/>\nsschost<br \/>\nsshost<br \/>\nssvch0st<br \/>\nssvchost<br \/>\nssvchost<br \/>\nssvichosst<br \/>\nst#host<br \/>\nstdhost<br \/>\nsuchost<br \/>\nsuchost<br \/>\nsuchostp<br \/>\nsuchostp<br \/>\nsuchosts<br \/>\nsuchosts<br \/>\nsv_host<br \/>\nsv\u00b1hest<br \/>\nsv0hoat<br \/>\nsv1host<br \/>\nsvahost<br \/>\nsvahost<br \/>\nsvcbost<br \/>\nsvcchost<br \/>\nsvcchost<br \/>\nsvcehost<br \/>\nsvcehost<br \/>\nsvcgest<br \/>\nsvcgh0st<br \/>\nsvcgoost<br \/>\nsvch0sat<br \/>\nsvch0sbt<br \/>\nsvch0set<br \/>\nsvch0sft<br \/>\nsvch0slt<br \/>\nsvch0smt<br \/>\nsvch0st<br \/>\nsvch0st<br \/>\nsvch0st_<br \/>\nsvch0sts<br \/>\nsvch7t<br \/>\nsvchaot<br \/>\nsvchast<br \/>\nsvchast<br \/>\nsvchcst<br \/>\nsvchcst<br \/>\nsvchest<br \/>\nsvchest<br \/>\nsvchhost<br \/>\nsvch\u00eest<br \/>\nsvchkost<br \/>\nsvcho<br \/>\nsvchobst<br \/>\nsvchoct<br \/>\nsvcholts<br \/>\nsvchon32<br \/>\nsvchoost<br \/>\nsvchoot<br \/>\nsvchort<br \/>\nsvchos<br \/>\nsvchos12<br \/>\nsvchosd<br \/>\nsvchosf<br \/>\nsvchosf<br \/>\nsvchosi<br \/>\nsvchosl<br \/>\nsvchoso<br \/>\nsvchosr<br \/>\nsvchoss<br \/>\nsvchosst<br \/>\nsvchost<br \/>\nsvchost<br \/>\nsvch\u00f6st<br \/>\nsvchost_<br \/>\nsvchost_cz<br \/>\nsvchost\u201d<br \/>\nsvchost0<br \/>\nsvchost1<br \/>\nsvchost10<br \/>\nsvchost16<br \/>\nsvchost2<br \/>\nsvchost2<br \/>\nsvchost3<br \/>\nsvchost3<br \/>\nsvchost31<br \/>\nsvchost32<br \/>\nsvchost32<br \/>\nsvchost4<br \/>\nsvchost5<br \/>\nsvchost6<br \/>\nsvchost64<br \/>\nsvchost64<br \/>\nsvchosta<br \/>\nsvchostbb<br \/>\nsvchostbd<br \/>\nsvchostbn<br \/>\nsvchostc<br \/>\nsvchostc32<br \/>\nsvchostcx<br \/>\nsvchostd<br \/>\nsvchostdll<br \/>\nsvchoste<br \/>\nsvchosted<br \/>\nsvchosti<br \/>\nsvchosting<br \/>\nsvchostit<br \/>\nsvchostl<br \/>\nsvchostms<br \/>\nsvchosto<br \/>\nsvchostr<br \/>\nsvchostre<br \/>\nsvchosts<br \/>\nsvchosts<br \/>\nsvchosts32<br \/>\nsvchostsr<br \/>\nsvchostss<br \/>\nsvchostt<br \/>\nsvchostt<br \/>\nsvchost\u00fe<br \/>\nsvchostun<br \/>\nsvchostv<br \/>\nsvchostv<br \/>\nsvchostxi<br \/>\nsvchostxi<br \/>\nsvchostxxx<br \/>\nsvchostz<br \/>\nsvchosv<br \/>\nsvchosy<br \/>\nsvchot<br \/>\nsvchoto<br \/>\nsvchots<br \/>\nsvchots<br \/>\nsvchott<br \/>\nsvchowb<br \/>\nsvchowt<br \/>\nsvchoxt<br \/>\nsvchoxt<br \/>\nsvchpst<br \/>\nsvchpst<br \/>\nsvchqs<br \/>\nsvchqst<br \/>\nsvchs0t<br \/>\nsvchsot<br \/>\nsvchsot<br \/>\nsvchsst<br \/>\nsvchssts<br \/>\nsvchst<br \/>\nsvchste<br \/>\nsvchsts<br \/>\nsvchtst<br \/>\nsvchust<br \/>\nsvchusts<br \/>\nsvcinit<br \/>\nsvcjhost<br \/>\nsvclost<br \/>\nsvcmost<br \/>\nsvcnost<br \/>\nsvcnost<br \/>\nsvcohst<br \/>\nsvcomst<br \/>\nsvcoost<br \/>\nsvcost<br \/>\nsvcpos<br \/>\nsvcroot<br \/>\nsvcroot<br \/>\nsvcshtost<br \/>\nsvcsoft<br \/>\nsvcsost<br \/>\nsvcst<br \/>\nsvctos<br \/>\nsvcxhost<br \/>\nsvdhost<br \/>\nsvdhost<br \/>\nsvdnost<br \/>\nsvehost<br \/>\nsvehost<br \/>\nsvgchost<br \/>\nsvggost<br \/>\nsvghost<br \/>\nsvghost<br \/>\nsvghosts<br \/>\nsvh0st<br \/>\nsvhcost<br \/>\nsvhest<br \/>\nsvhoct<br \/>\nsvhosit<br \/>\nsvhosr<br \/>\nsvhosst<br \/>\nsvhost<br \/>\nsvhost<br \/>\nsvhost1<br \/>\nsvhost2<br \/>\nsvhostc<br \/>\nsvhoste<br \/>\nsvhostr<br \/>\nsvhosts<br \/>\nsvhostt<br \/>\nsvhostu<br \/>\nsvhot<br \/>\nsvhst<br \/>\nsvhust<br \/>\nsvichosst<br \/>\nsvichost<br \/>\nsvlhost<br \/>\nsvnchost<br \/>\nsvnhost<br \/>\nsvohcst<br \/>\nsvohcst<br \/>\nsvohost<br \/>\nsvohost<br \/>\nsvohst<br \/>\nsvost<br \/>\nsvphost<br \/>\nsvphost<br \/>\nsvphostu<br \/>\nsvphostu<br \/>\nsvrhost<br \/>\nsvrhost<br \/>\nsvschost<br \/>\nsvschost<br \/>\nsvschosta<br \/>\nsvsh0st<br \/>\nsvsh0st<br \/>\nsvshoct<br \/>\nsvshost<br \/>\nsvshost<br \/>\nsvshosti<br \/>\nsvshosts<br \/>\nsvshot<br \/>\nsvuhost<br \/>\nsvvchcst<br \/>\nsvvchost<br \/>\nsvvghost<br \/>\nsvvhost<br \/>\nsvvhost<br \/>\nsvvhosti<br \/>\nsvwhost<br \/>\nsvxhos<br \/>\nsvxhost<br \/>\nswchost<br \/>\nswchost<br \/>\nswdhost<br \/>\nswhost<br \/>\nswhost<br \/>\nsxhost<br \/>\nsxhost<br \/>\nsychost<br \/>\nsynchost<br \/>\nsynchost<br \/>\nsynhost<br \/>\nsyschost<br \/>\nsyschost<br \/>\nsyshost<br \/>\nsyshost<br \/>\nszchostc<br \/>\nszchostc<br \/>\ntsvchost<br \/>\nusvchost<br \/>\nuvchost<br \/>\nvcchost<br \/>\nvchost<br \/>\nvhchost<br \/>\nvhost<br \/>\nvschost<br \/>\nvshost<br \/>\nvsschost<br \/>\nvxhost<br \/>\nwsvchost<br \/>\nwvchosd<br \/>\nxvshost<br \/>\nzvchost<\/p>\n<p><strong>win.exe (and similar\/related names)<\/strong><\/p>\n<p>mswin<br \/>\nwin_<br \/>\nwin_5<br \/>\nwin00<br \/>\nwin01<br \/>\nwin07<br \/>\nwin08<br \/>\nwin09<br \/>\nwin1<br \/>\nwin10<br \/>\nwin11<br \/>\nwin16<br \/>\nwin2<br \/>\nwin22<br \/>\nwin23<br \/>\nwin3<br \/>\nwin30<br \/>\nwin32<br \/>\nwin39<br \/>\nwin4<br \/>\nwin42<br \/>\nwin44<br \/>\nwin45<br \/>\nwin5<br \/>\nwin54<br \/>\nwin55<br \/>\nwin62<br \/>\nwin64<br \/>\nwin7<br \/>\nwin76<br \/>\nwin77<br \/>\nwin8<br \/>\nwin91<br \/>\nwin96<br \/>\nwin98<br \/>\nwin9x<br \/>\nwina<br \/>\nwinad<br \/>\nwinar<br \/>\nwinav<br \/>\nwinb<br \/>\nwinc<br \/>\nwince<br \/>\nwind<br \/>\nwind3<br \/>\nwindf<br \/>\nwindm<br \/>\nwinds<br \/>\nwine<br \/>\nwinet<br \/>\nwinex<br \/>\nwinfc<br \/>\nwingb<br \/>\nwings<br \/>\nwingt<br \/>\nwinhd<br \/>\nwinhv<br \/>\nwini<br \/>\nwinit<br \/>\nwink<br \/>\nwinkl<br \/>\nwinl<br \/>\nwinlc<br \/>\nwinma<br \/>\nwinmm<br \/>\nwinmn<br \/>\nwinmx<br \/>\nwinn<br \/>\nwinn1<br \/>\nwinns<br \/>\nwinnt<br \/>\nwinny<br \/>\nwinog<br \/>\nwinok<br \/>\nwinos<br \/>\nwinow<br \/>\nwinp9<br \/>\nwinpc<br \/>\nwinr<br \/>\nwinra<br \/>\nwinrm<br \/>\nwinrr<br \/>\nwins<br \/>\nwins7<br \/>\nwinsh<br \/>\nwinsp<br \/>\nwinss<br \/>\nwinst<br \/>\nwint<br \/>\nwinu<br \/>\nwinud<br \/>\nwinup<br \/>\nwinvc<br \/>\nwinvr<br \/>\nwinw<br \/>\nwinwl<br \/>\nwinwn<br \/>\nwinws<br \/>\nwinx<br \/>\nwinxp<br \/>\nwinxv<br \/>\nwinz<\/p>\n<p><strong>winlogon.exe<\/strong><\/p>\n<p>_winlogon<br \/>\ninlogon<br \/>\nnlogon<br \/>\nwgalogon<br \/>\nwimlogom<br \/>\nwin_logn<br \/>\nwin1ogo<br \/>\nwin1ogon<br \/>\nwin1ogons<br \/>\nwindlogon<br \/>\nwiniogon<br \/>\nwinl0g0n<br \/>\nwinl0gin<br \/>\nwinl0gon<br \/>\nwinlgon<br \/>\nwinligon<br \/>\nwinlngon<br \/>\nwinlog<br \/>\nwinlog056<br \/>\nwinlog0n<br \/>\nwinlog1<br \/>\nwinlogan<br \/>\nwinloge<br \/>\nwinlogen<br \/>\nwinloger<br \/>\nwinlogin<br \/>\nwinlogins<br \/>\nwinlogn<br \/>\nwinlogo<br \/>\nwinlogom<br \/>\nwinlogoms<br \/>\nwinlogon1<br \/>\nwinlogon3<br \/>\nwinlogon32<br \/>\nwinlogon6<br \/>\nwinlogon86<br \/>\nwinlogone<br \/>\nwinlogonl<br \/>\nwinlogonn<br \/>\nwinlogonpc<br \/>\nwinlogonr<br \/>\nwinlogons<br \/>\nwinlogor<br \/>\nwinlogr<br \/>\nwinlogs<br \/>\nwinlogun<br \/>\nwinlongon<br \/>\nwinlugan<br \/>\nwinslogin<br \/>\nwnilogon<br \/>\nwnlgon<br \/>\nwnlogin<\/p>\n","protected":false},"excerpt":{"rendered":"<p>In my old post I described a list of file names used by malware to impersonate svchost.exe. I thought I will re-visit this post today and provide some more file names that malware is using for impersonation of common file &hellip; <a href=\"https:\/\/www.hexacorn.com\/blog\/2015\/12\/18\/the-typographical-and-homomorphic-abuse-of-svchost-exe-and-other-popular-file-names\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[28,39,19,9],"tags":[],"_links":{"self":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts\/3430"}],"collection":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/comments?post=3430"}],"version-history":[{"count":2,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts\/3430\/revisions"}],"predecessor-version":[{"id":3432,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts\/3430\/revisions\/3432"}],"wp:attachment":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/media?parent=3430"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/categories?post=3430"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/tags?post=3430"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}