Execution
T1047 has_wmi: Executes one or several WMI requests
Privilege Escalation
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
Defense Evasion
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1480 system_default_lang_id_present: Checks the system language
Credential Access
T1552.001 infostealer_bitcoin: Attempts to obtain access to Bitcoin/ALTCoin wallets
Discovery
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
Impact
T1486 modifies_files: Cryptolocker indicators detected (renamed 100 or more files)
T1485 deletes_files: Removes 100 or more files from C: drive
T1486 ransomware_message: Ransomware indicators detected (possible ransom message creation)
Other
no_graphical_activity: No graphic activity
break_limit_exceeded: Warning: function calls limit has been exceeded
writes_data: Writes big amount of data to disk
pe_overlay: PE file contains overlay
yara_rules: Static rules