PE exports mimic Print Spooler RPC (module name “spoolsv.exe”), unusual “.fothk” INT3 section, token APIs — is this a known malicious spooler-trojan pattern?
John William Dezell
0
Reputation points
- Version/Environment: Offline static analysis only; no live sandbox here.
- Problem summary:
- 64-bit PE with 225 exports matching spooler RPC symbols and module name “spoolsv.exe”; imports include CreateProcessAsUserW, AdjustTokenPrivileges, IsDebuggerPresent; .fothk section full of INT3.
- No embedded C2; suspected role is service/persistence via spooler. Looking for Microsoft’s recognition/guidance. [redacted]_Exploit.exe Technica…
- Evidence: Export table, imports, strings indicating ALPC/PrintSpoolerIPC; registry keys that would be abused (Print Processors/Port Monitors) noted for hunting. [redacted]_Exploit.exe Technica…
- What I’ve tried: Enumerated imports/exports/strings; hypothesized behavior and ATT&CK mapping. [redacted]_Exploit.exe Technica…
- Specific questions:
- Does Microsoft classify binaries that export spooler RPC tables and masquerade as “spoolsv.exe” (from non-system path) as a known attack technique, and are there official detections/hardening steps (e.g., allowed path policies for spooler image)? [redacted]_Exploit.exe Technica…
- Recommended telemetry (event IDs, registry, ETW) to definitively prove spooler service replacement or malicious Print Processor/Port Monitor registration? [redacted]_Exploit.exe Technica…
- Any supported way to lock down print autostarts (T1547.010/.012) across a fleet without breaking legitimate printing? [redacted]_Exploit.exe Technica…
- Attachments: “[redacted]_Exploit.exe Technical Analysis.docx” (hashes included). [redacted]_Exploit.exe Technica…
TL;DR: Need Microsoft confirmation and concrete defenses for a suspected spooler-masquerading service binary that exports spooler RPC and uses token APIs. [redacted]_Exploit.exe Technica…
Windows for home | Windows 11 | Security and privacy
Sign in to answer