Persistence
T1574.011 persistence_services: Modifies Services registry key
T1543.003 persistence_services: Modifies Services registry key
Privilege Escalation
T1574.011 persistence_services: Modifies Services registry key
T1543.003 persistence_services: Modifies Services registry key
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
Defense Evasion
T1036.001 invalid_authenticode: Digital signature of the executable file has failed the verification
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1574.011 persistence_services: Modifies Services registry key
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
Discovery
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
Impact
T1489 stops_service: Stops Windows services
Other
yara_rules: Static rules
driver_load: Loads a driver
unsigned_driver_drop: Sample is not signed and drops a device driver
no_graphical_activity: No graphic activity
require_administrator: Requests administrator privileges
has_pdb: This executable file has a PDB path
message_box: Displays a message
pe_overlay: PE file contains overlay
enables_execute_access_on_stack: Enable execution access on stack
many_files_in_archive: The archive contains more than 5 files