LoFP LoFP / t1195.002

t1195.002

TitleTags
custom or portable notepad++ installations in non-standard directories.
false positives may be present based on file version, modify the analytic to only look for version between 18.12.407 and 18.12.416 as needed.
false positives will be present for accessing the 3cx[.]com website. remove from the lookup as needed.
legitimate update processes creating temporary files in unexpected locations.
low but possible. generic filenames like cloud.json or environment.json may appear in legitimate contexts. correlate with npm install activity or suspicious parent processes.
other legitimate query to official domains not listed in the filter, needing tuning.
some legitimate network misconfigurations or proxy issues causing unexpected dns queries.
there may be false positives generated due to the reliance on version numbers for identification purposes. despite this limitation, the primary goal of this approach is to aid in the detection of the software within the environment.
unlikely