notice |
Str_Win32_Http_API |
Match Windows Http API call |
memory |
notice |
Str_Win32_Internet_API |
Match Windows Inet API call |
memory |
info |
anti_dbg |
Checks if being debugged |
memory |
info |
antisb_threatExpert |
Anti-Sandbox checks for ThreatExpert |
memory |
info |
Check_Dlls |
(no description) |
memory |
info |
DebuggerCheck__QueryInfo |
(no description) |
memory |
info |
ThreadControl__Context |
(no description) |
memory |
info |
win_hook |
Affect hook table |
memory |
info |
create_com_service |
Create a COM server |
memory |
info |
cred_local |
Steal credential |
memory |
info |
escalate_priv |
Escalade priviledges |
memory |
info |
keylogger |
Run a keylogger |
memory |
info |
Microsoft_Office_Document_Zero |
Microsoft Office Document Signature Zero |
binaries (upload) |
info |
migrate_apc |
APC queue tasks migration |
memory |
info |
network_dga |
Communication using dga |
memory |
info |
network_dns |
Communications use DNS |
memory |
info |
network_ftp |
Communications over FTP |
memory |
info |
network_http |
Communications over HTTP |
memory |
info |
network_tcp_listen |
Listen for incoming communication |
memory |
info |
network_tcp_socket |
Communications over RAW socket |
memory |
info |
rat_rdp |
Remote Administration toolkit enable RDP |
memory |
info |
screenshot |
Take screenshot |
memory |
info |
spreading_file |
Malware can spread east-west file |
memory |
info |
Str_Win32_Wininet_Library |
Match Windows Inet API library declaration |
memory |
info |
Str_Win32_Winsock2_Library |
Match Winsock 2 API library declaration |
memory |
info |
win_files_operation |
Affect private profile |
memory |
info |
win_mutex |
Create or check mutex |
memory |
info |
win_private_profile |
Affect private profile |
memory |
info |
win_registry |
Affect system registries |
memory |
info |
win_token |
Affect system token |
memory |