svhost.exe

Malware updated 5 months ago (2024-05-05T07:17:42.668Z)
Download STIX
Preview STIX
Svhost.exe is a type of malware, specifically designed to exploit and damage computer systems. It infiltrates your system through suspicious downloads, emails, or websites, often unbeknownst to the user. Once inside, it unzips its contents, dropping another PowerShell loader script "core.ps1," an encrypted file (ENC-2), and an Ethash miner called PhoenixMiner executable with "svhost.exe" as the filename. This harmful program can steal personal information, disrupt operations, or even hold your data hostage for ransom. The attacker cleverly uses the filename "svhost.exe," which closely resembles the legitimate Windows executable filename "svchost.exe" located in the Windows systems folder. This tactic is likely employed to avoid detection by malicious process-scanning engines of endpoint security products. By mimicking a legitimate system process, the malware can operate without raising immediate suspicion, thereby increasing its potential to cause significant damage. Furthermore, the Medusa Locker ransomware duplicates its malicious executable as either "svhost.exe" or "svchostt.exe" within the user's roaming application data directory (%AppData%\Roaming). This strategy establishes persistence and ensures that the malware runs during system start-up, allowing it to continue encrypting files. This persistent presence on the system further enhances the malware's ability to carry out its malicious activities over extended periods.
Description last updated: 2024-05-05T06:35:01.530Z
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the svhost.exe Malware was read from the documents corpus below. This display is limited to 20 results, create a free account to see more