Persistence
T1574 dropper_dll: Creates DLL, which is then loaded into the process
Privilege Escalation
T1574 dropper_dll: Creates DLL, which is then loaded into the process
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
Defense Evasion
T1027.002 unnamed_memory_regions_contains_pe: One or several unnamed memory regions are PE files
T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1027.002 packer_aspack: Executable file is packed with ASPack
T1574 dropper_dll: Creates DLL, which is then loaded into the process
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
Discovery
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
Other
yara_rules: Static rules
network_bind: Starts servers listening at 127.0.0.1:2143, 127.3.12.242:8111, 127.3.12.242:8112, 127.3.12.242:8113, 127.3.12.242:8114, 127.3.12.242:8115, 127.3.12.242:8116, 127.3.12.242:8117, 127.3.12.242:8118, 127.3.12.240:8536, 127.3.12.240:8537, 127.3.12.240:5841, 127.3.12.240:5842, 127.3.12.240:8174, 127.3.12.240:8175, 127.3.12.240:8121, 127.3.12.240:8122, 127.3.12.240:8322, 127.3.12.240:8323, 127.3.12.240:8522, 127.3.12.240:8523, 127.3.12.242:8181, 127.3.12.242:8182, 127.3.12.242:8183, 127.3.12.242:8184, 127.3.12.242:8185, 127.3.12.242:8186, 127.3.12.242:8187, 127.3.12.242:8188, 127.3.12.242:9600, 127.3.12.242:9601, 127.3.12.242:9603, 127.3.12.242:9602, 127.3.12.242:9604, 127.3.12.242:9605, 127.3.12.242:9606, 127.3.12.242:9607, 127.3.12.242:9608, 127.3.12.242:9609, 127.3.12.242:9610, 127.3.12.242:9011, 127.3.12.242:9611, 127.3.12.242:9612, 127.3.12.242:9613, 127.3.12.242:9614
creates_exe: Creates executable files in the file system
process_crashed: One of the processes has failed
no_graphical_activity: No graphic activity
require_administrator: Requests administrator privileges
message_box: Displays a message
test_check_service: Starts services
suricata_alert: Malicious traffic detected