Execution
T1053.005 creates_tasks: Creates a delayed task using Task Scheduler
T1053.005 persistence_autorun: Makes itself run automatically on Windows startup
T1059.007 bad_js: Suspicious Javascript file
T1059.003 executes_dropped_cmd: Executes dropped batch files
T1059.006 drops_python_dll: Drops python dll
Persistence
T1053.005 creates_tasks: Creates a delayed task using Task Scheduler
T1053.005 persistence_autorun: Makes itself run automatically on Windows startup
T1547.004 persistence_autorun: Makes itself run automatically on Windows startup
T1574.001 dll_hijacking: Indicators of DLL Hijacking vulnerability exploitation detected (creates a typical file)
T1574.011 persistence_services: Modifies Services registry key
T1543.003 persistence_services: Modifies Services registry key
T1574 dropper_dll: Creates DLL, which is then loaded into the process
Privilege Escalation
T1053.005 creates_tasks: Creates a delayed task using Task Scheduler
T1548.002 uac_bypass_mocking_dir: UAC bypass with the use of mocking directory
T1053.005 persistence_autorun: Makes itself run automatically on Windows startup
T1547.004 persistence_autorun: Makes itself run automatically on Windows startup
T1574.001 dll_hijacking: Indicators of DLL Hijacking vulnerability exploitation detected (creates a typical file)
T1574.011 persistence_services: Modifies Services registry key
T1543.003 persistence_services: Modifies Services registry key
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1574 dropper_dll: Creates DLL, which is then loaded into the process
Defense Evasion
T1548.002 uac_bypass_mocking_dir: UAC bypass with the use of mocking directory
T1564.001 hides_original_file: Makes original executable file hidden
T1574.001 dll_hijacking: Indicators of DLL Hijacking vulnerability exploitation detected (creates a typical file)
T1564.001 stealth_file: Creates hidden or system files
T1497.001 antivm_disk_size: Checks the amount of free disk space
T1574.011 persistence_services: Modifies Services registry key
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1574 dropper_dll: Creates DLL, which is then loaded into the process
Credential Access
T1555.004 windows_credential_manager: Acquire credentials from the Windows Credential Manager
T1056.001 infostealer_keylogger: Keylogger (intercepts keystrokes)
Discovery
T1497.001 antivm_disk_size: Checks the amount of free disk space
Collection
T1056.001 infostealer_keylogger: Keylogger (intercepts keystrokes)
Impact
T1529 shutdown_system: Shuts the system down
Other
yara_rules: Static rules
ransomware_bcdedit: Runs bcdedit commands specific to ransomware
creates_exe: Creates executable files in the file system
executes_dropped_exe: Executes dropped exe files
create_rpc_bindings: Creates RPC connection
creates_suspended_process: Creates suspended process
message_box: Displays a message
error_drawtext: An error occured while executing the file
test_check_service: Starts services
checktokenmembership: Checks user token with CheckTokenMembership call
pe_overlay: PE file contains overlay
static_big_overlay: Executable file contains an enormously big overlay