Execution
T1204 suspicious_lnk: LNK file with suspicious content
Privilege Escalation
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
Defense Evasion
T1222 takeown: May obtain file ownership using the takeown.exe tool
T1070 stealth_webhistory: Clears browsing history
T1070.004 self_removal_command: Executes command to delete itself
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
Credential Access
T1552.002 opens_registry_hive_file: Attempts to open Windows registry hive file
T1003.002 opens_registry_hive_file: Attempts to open Windows registry hive file
T1552 cookie_files: Accesses cookie files
T1555.003 cookie_files: Accesses cookie files
Impact
T1485 deletes_files: Removes 500 or more files from C: drive
Other
unexpected_exception: Unexpected exception
creates_suspended_process: Creates suspended process
get_policy_info: Retrieves information about a Policy object
checktokenmembership: Checks user token with CheckTokenMembership call
yara_rules: Static rules