• CommunityEnterprisePlans
  • Intel Exchange
    Intel ExchangeDetections
  • Resources
  • About
  • Leaderboard
Join CommunitySign In
    All Detections

    LockAppHost Spawns Suspended nslookup.exe/svchost.exe for Hidden Miner

    avatar
    GlassDiceBearhttps://www.dicebear.comhttps://creativecommons.org/publicdomain/zero/1.0/„Glass” (https://www.dicebear.com) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)
    Arnold Chan@slaz
    •updated Sep 6, 2026•0•0•0

    Detects suspicious executions of 'nslookup.exe' and 'svchost.exe' when triggered by the Windows LockAppHost process. This pattern is indicative of potential process injection or masquerading attempts by malicious actors using legitimate system processes as proxies for unauthorized activity.

    Microsoft Sentinel (KQL)

    Tags

    T1059 - Command and Scripting InterpreterTA0002 - ExecutionProcess CreationCommand ExecutionWindowsWindows Defender Atpkql

    Found in

    • REVSTEALER Infostealer Ramps Up With Follow-on ModulesLast updated Sep 7, 2026
    • REVSTEALER: Sophisticated Infostealer with Polygon C2 ResilienceLast updated Sep 6, 2026
    • REVSTEALER: Sophisticated Infostealer with Polygon C2 ResilienceLast updated Sep 6, 2026
    • REVSTEALER: Sophisticated Infostealer with Polygon C2 ResilienceLast updated Sep 6, 2026

    Community Inspired.
    AI Enhanced.
    Better Detections.

    Follow Us

    Company

    • About
    • Leaderboard

    Product

    • Community
    • Enterprise
    • Plans

    © 2026 Copyright. All Rights Reserved.

    Privacy PolicyTerms of Service

    Sign up to view this detection

    or

    Already have an account?