EternalBlue
DoublePulsar SMB implant, MS17-010 vulnerability
RAT / C2
Meterpreter, Cobalt Strike, njRAT, DarkComet, Quasar, AsyncRAT, Gh0st, Poison Ivy
Shell Backdoors
Netcat listeners, bind shells, telnet backdoors, rogue SSH
Web Shells
PHP/ASP/JSP shells on HTTP services
Proxies
SOCKS, HTTP proxies, tunnels used as pivot points
Miners
Cryptocurrency mining stratum connections