mttaggart / wtfbins

WTF are these binaries doing?! A list of benign applications that mimic malicious behavior.
MIT License
149 stars 12 forks source link

[New WTFBin]: Teramind dwm.exe #55

Open WizardShotTheFood opened 1 month ago

WizardShotTheFood commented 1 month ago

(Note that I have personally observed rundll32.exe in the same location; however, I have not yet been able to find any formal documentation of this behavior.)

WizardShotTheFood commented 1 month ago

This was the response I got when I asked Teramind's support if the rundll32.exe file was theirs. I'm not sure if this will suffice for documentation, but it's the best I've got right now. image