Defense Evasion
T1027.002 packer_entropy: Probably contains compressed or encrypted data
Other
yara_rules: Static rules
ce_info: Blackcat Configuration Data found
suspicious_network_port: Performs TCP or UDP request to non-standard port
pe_overlay: PE file contains overlay