Execution
T1053.005 creates_tasks: Creates a delayed task using Task Scheduler
T1204 suspicious_lnk: LNK file with suspicious content
T1053.005 persistence_autorun: Makes itself run automatically on Windows startup
T1059.005 mshta_vbscript: Runs VBScript using mshta
T1059.003 suspicious_cmd: Executes cmd.exe with a suspicious command line
Persistence
T1053.005 creates_tasks: Creates a delayed task using Task Scheduler
T1053.005 persistence_autorun: Makes itself run automatically on Windows startup
Privilege Escalation
T1053.005 creates_tasks: Creates a delayed task using Task Scheduler
T1053.005 persistence_autorun: Makes itself run automatically on Windows startup
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
Defense Evasion
T1218.005 mshta_vbscript: Runs VBScript using mshta
T1027 suspicious_cmd: Executes cmd.exe with a suspicious command line
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
Discovery
T1082 reads_csrss: Attempts to read csrss.exe memory
Command and Control
T1105 cmdline_curl: Uses curl utility for network data transferring
Other
yara_rules: Static rules
unexpected_exception: Unexpected exception
no_graphical_activity: No graphic activity
creates_suspended_process: Creates suspended process
message_box: Displays a message
get_policy_info: Retrieves information about a Policy object