Execution
T1053.005 persistence_autorun: Makes itself run automatically on Windows startup
T1047 has_wmi: Executes one or several WMI requests
T1059.001 powershell_through_runspace: Executes PowerShell script without spawning powershell.exe process
T1047 antivm_wmi: Uses WMI to detect virtual environment
Persistence
T1053.005 persistence_autorun: Makes itself run automatically on Windows startup
T1547.001 persistence_autorun: Makes itself run automatically on Windows startup
T1547.004 persistence_autorun: Makes itself run automatically on Windows startup
T1547 persistence_bootexecute: Installs a native application to be launched at Windows startup
Privilege Escalation
T1053.005 persistence_autorun: Makes itself run automatically on Windows startup
T1547.001 persistence_autorun: Makes itself run automatically on Windows startup
T1547.004 persistence_autorun: Makes itself run automatically on Windows startup
T1547 persistence_bootexecute: Installs a native application to be launched at Windows startup
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
Defense Evasion
T1497.001 antivm_wmi: Uses WMI to detect virtual environment
T1562 firewall_disable: Disables Firewall
T1497 evasion_winlogon: Attempts to detect Sandbox by winlogon sessions
T1497 evasion_sru: Attempts to detect Sandbox by process activity difference
T1497.001 antivm_generic_productname: Checks system product name in registry, possibly for anti-virtualization
T1070 stealth_window: A process created a hidden window
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
Credential Access
T1552.002 opens_registry_hive_file: Attempts to open Windows registry hive file
T1003.002 opens_registry_hive_file: Attempts to open Windows registry hive file
Discovery
T1082 has_wmi: Executes one or several WMI requests
T1497.001 antivm_wmi: Uses WMI to detect virtual environment
T1057 process_interest: Enumerates processes
T1082 uses_windows_utilities: Uses Windows utilities for basic Windows functionality
T1518 locates_browser: Attempts to identify where browsers are installed
T1497 evasion_winlogon: Attempts to detect Sandbox by winlogon sessions
T1497 evasion_sru: Attempts to detect Sandbox by process activity difference
T1497.001 antivm_generic_productname: Checks system product name in registry, possibly for anti-virtualization
Impact
T1565 modifies_hostfile: Writes data to system hosts file
T1486 modifies_files2: Cryptolocker indicators detected (500 or more files are modified)
T1490 vssadmin_delete_shadows: Attempt to delete volume shadow copies
T1485 deletes_files: Removes 500 or more files from C: drive
T1490 wbadmin_delete_backup: Removes system backup copies using wbadmin utility
Other
ransomware_shadowcopy: Removes volume shadow copies
ransomware_bcdedit: Runs bcdedit commands specific to ransomware
creates_in_windows: Creates files in the Windows directory
copies_self: Creates a copy of itself
bitcoin_opencl: Installs the OpenCL library, possibly to mine bitcoins
creates_exe: Creates executable files in the file system
create_process_failed: Could not start the process
has_pdb: This executable file has a PDB path
creates_suspended_process: Creates suspended process
test_check_service: Starts services
writes_data: Writes big amount of data to disk
yara_rules: Static rules