Defense Evasion
T1027.002 packer_polymorphic: Creates a modified copy of itself
T1497 evasion_diskenum: Sandbox evasion using enumeration of partitions
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1574 dropper_dll: Creates DLL, which is then loaded into the process
Other
yara_rules: Static rules
creates_in_windows: Creates files in the Windows directory
network_bind: Starts servers listening at 0.0.0.0:3127, 0.0.0.0:3128, 0.0.0.0:3129, 0.0.0.0:3130, 0.0.0.0:3131, 0.0.0.0:3132, 0.0.0.0:3133, 0.0.0.0:3134, 0.0.0.0:3135, 0.0.0.0:3136, 0.0.0.0:3137, 0.0.0.0:3138, 0.0.0.0:3139, 0.0.0.0:3140, 0.0.0.0:3141, 0.0.0.0:3142, 0.0.0.0:3143, 0.0.0.0:3144, 0.0.0.0:3145, 0.0.0.0:3146, 0.0.0.0:3147, 0.0.0.0:3148, 0.0.0.0:3149, 0.0.0.0:3150, 0.0.0.0:3151, 0.0.0.0:3152, 0.0.0.0:3153, 0.0.0.0:3154, 0.0.0.0:3155, 0.0.0.0:3156, 0.0.0.0:3157, 0.0.0.0:3158, 0.0.0.0:3159, 0.0.0.0:3160, 0.0.0.0:3161, 0.0.0.0:3162, 0.0.0.0:3163, 0.0.0.0:3164, 0.0.0.0:3165, 0.0.0.0:3166, 0.0.0.0:3167, 0.0.0.0:3168, 0.0.0.0:3169, 0.0.0.0:3170, 0.0.0.0:3171, 0.0.0.0:3172, 0.0.0.0:3173, 0.0.0.0:3174, 0.0.0.0:3175, 0.0.0.0:3176, 0.0.0.0:3177, 0.0.0.0:3178, 0.0.0.0:3179, 0.0.0.0:3180, 0.0.0.0:3181, 0.0.0.0:3182, 0.0.0.0:3183, 0.0.0.0:3184, 0.0.0.0:3185, 0.0.0.0:3186, 0.0.0.0:3187, 0.0.0.0:3188, 0.0.0.0:3189, 0.0.0.0:3190, 0.0.0.0:3191, 0.0.0.0:3192, 0.0.0.0:3193, 0.0.0.0:3194, 0.0.0.0:3195, 0.0.0.0:3196, 0.0.0.0:3197, 0.0.0.0:3198, 0.0.0.0:3199
creates_exe: Creates executable files in the file system
network_ftp: Performs FTP requests
has_pdb: This executable file has a PDB path
creates_suspended_process: Creates suspended process
break_limit_exceeded: Warning: function calls limit has been exceeded
test_check_service: Starts services
copies_self: Creates a copy of itself
writes_data: Writes big amount of data to disk