Stordiag.exe

Storage diagnostic tool

Paths

  • c:\windows\system32\stordiag.exe
  • c:\windows\syswow64\stordiag.exe

Commands

Execute

Once executed, Stordiag.exe will execute schtasks.exe systeminfo.exe and fltmc.exe - if stordiag.exe is copied to a folder and an arbitrary executable is renamed to one of these names, stordiag.exe will execute it.

Use case: Possible defence evasion purposes.

Privileges: User

stordiag.exe

Execute

Once executed, Stordiag.exe will execute schtasks.exe and powershell.exe - if stordiag.exe is copied to a folder and an arbitrary executable is renamed to one of these names, stordiag.exe will execute it.

Use case: Possible defence evasion purposes.

Privileges: User

stordiag.exe

Detection

Resources