Privilege Escalation T1055.012 injection_runpe: Injects code into another process
T1055 injection_runpe_2: Executes injected code in another process
T1055 sets_debug_registers: Sets debug registers for a thread in a different process
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
Defense Evasion T1055.012 injection_runpe: Injects code into another process
T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1055 injection_runpe_2: Executes injected code in another process
T1055 sets_debug_registers: Sets debug registers for a thread in a different process
T1497.001 antivm_disk_size: Checks the amount of free disk space
T1070 stealth_window: A process created a hidden window
T1497.001 antivm_network_adapters: Checks NIC addresses
T1480 system_default_lang_id_present: Checks the system language
T1027.002 nsis_archive: One of the packages is NSIS archive
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1497.001 antivm_queries_computername: Retrieves the computer name
Credential Access T1552 infostealer_im: Collects information about installed messengers
T1503 infostealer_browser: Retrieves personal information from local Internet browsers
T1552 infostealer_mail: Collects personal data from local email clients
T1552 infostealer_browser: Retrieves personal information from local Internet browsers
T1552 infostealer_ftp: Collects data from local FTP clients
Discovery T1497.001 antivm_disk_size: Checks the amount of free disk space
T1497.001 antivm_network_adapters: Checks NIC addresses
T1497.001 antivm_queries_computername: Retrieves the computer name
Collection T1114 infostealer_mail: Collects personal data from local email clients
Command and Control T1071.001 network_http: Performs HTTP requests
Other suricata_alert: Malicious traffic detected
ip_domains: Identifies an IP address using external resources
executes_dropped_exe: Executes dropped exe files
only_exec_in_archive: The archive contains only an executable file
telegram_api: Telegram Messenger API is used
no_graphical_activity: No graphic activity
yara_rules: Static rules
creates_suspended_process: Creates suspended process
creates_exe: Creates executable files in the file system
test_check_service: Starts services
checktokenmembership: Checks user token with CheckTokenMembership call
pe_overlay: PE file contains overlay