Execution
T1059.003 suspicious_cmd_process: Cmd.exe without commandline launches a new process
T1047 has_wmi: Executes one or several WMI requests
T1106 susp_callbacks: Suspicious usage of some WinAPI with callbacks
Persistence
T1547.001 persistence_autorun: Makes itself run automatically on Windows startup
Privilege Escalation
T1547.001 persistence_autorun: Makes itself run automatically on Windows startup
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
Defense Evasion
T1070.004 deletes_self: Moves to different location or removes the original executable file
T1027.002 decompress_pefile: Unpacks a PE file into memory
T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1140 decompress_pefile: Unpacks a PE file into memory
T1497.001 antivm_disk_size: Checks the amount of free disk space
T1497.003 antisandbox_sleep_utilities: Uses Windows utilities for pausing the execution
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1027.002 pe_features: Executable file has PE anomalies (may be false positive)
T1497.001 antivm_queries_computername: Retrieves the computer name
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1480 system_default_lang_id_present: Checks the system language
Credential Access
T1552 infostealer_mail: Collects personal data from local email clients
T1552 infostealer_browser: Retrieves personal information from local Internet browsers
T1552.001 infostealer_bitcoin: Attempts to obtain access to Bitcoin/ALTCoin wallets
T1503 infostealer_browser: Retrieves personal information from local Internet browsers
T1555.003 cookie_files: Accesses cookie files
T1555.004 windows_credential_manager: Acquire credentials from the Windows Credential Manager
T1552 cookie_files: Accesses cookie files
Discovery
T1518.001 antiav_detectreg: Attempts to detect installed antiviruses by a certain registry key
T1497.001 antivm_disk_size: Checks the amount of free disk space
T1497.003 antisandbox_sleep_utilities: Uses Windows utilities for pausing the execution
T1083 crawls_directories: Opens a huge number of directories all over disk C: (possibly, searches for sensitive data)
T1082 uses_windows_utilities: Uses Windows utilities for basic Windows functionality
T1518.001 wmi_check_av: Uses WMI to check for installed antivirus software
T1518 locates_browser: Attempts to identify where browsers are installed
T1497.001 antivm_queries_computername: Retrieves the computer name
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1016.001 system_network_configuration_discovery: System network configuration discovery detected
Collection
T1113 screenshot_file: Possibly, makes a screenshot and saves it to a file
T1114 infostealer_mail: Collects personal data from local email clients
T1074.001 access_recyclebin: Manipulation with recyclebin detected
Command and Control
T1095 network_icmp: Creates ICMP traffic
T1568.002 dga_domains: Connects to DGA domains
T1071.001 network_http: Performs HTTP requests
T1071.001 winhttp_https: Performs HTTP/HTTPS requests using WinHttp
T1071.001 wininet_https: Performs HTTP/HTTPS requests using WinInet
Exfiltration
T1022 encrypts_pc_info: Collects and encrypts information about the computer (possibly for exfiltration)
Impact
T1486 ransomware_windows_possible: Ransomware indicators detected (possible ransom window creation)
T1486 modifies_files: Cryptolocker indicators detected (renamed 500 or more files)
T1486 modifies_files2: Cryptolocker indicators detected (100 or more files are modified)
T1485 deletes_files: Removes 500 or more files from C: drive
T1486 mass_data_encryption: Encrypts data using the same key (possible ransomware behaviour)
T1486 ransomware_message: Ransomware indicators detected (possible ransom message creation)
Other
yara_rules: Static rules
suricata_alert: Malicious traffic detected
cerber_behavior: Exhibits behavior characteristic of Cerber ransomware
static_pe_anomaly: The PE file structure contains anomalies
runs_utility_without_cmdline: Runs system utility without arguments (non-typical usage)
copies_self: Creates a copy of itself
cryptolocker_wallpaper: Ransomware indicators detected (changes the desktop wallpaper file)
generic_phish: Network traffic contains indicators of website cloning
dns_tld_pw: Connects to TLD .PW, possibly malware
creates_exe: Creates executable files in the file system
suspicious_process_network: Unusual process network activity detected
dns_without_resolve: DNS query without a response
dead_host: Connects to IP addresses that do not respond to requests
executes_dropped_exe: Executes dropped exe files
process_crashed: One of the processes has failed
dotnet_suspicious_resources_names: Dotnet program has suspicious resources names
create_rpc_bindings: Creates RPC connection
require_administrator: Requests administrator privileges
dotnet_embeded_dependencies_by_costura: Dotnet program has embedded dependencies by Costura
creates_suspended_process: Creates suspended process
dotnet_import_unmanaged_code: Dotnet program statically imports unmanaged functions/modules
break_limit_exceeded: Warning: function calls limit has been exceeded
message_box: Displays a message
origin_langid: Unconventional language of the executable file
creates_in_programdata: Creates files in the ProgramData directory
test_check_service: Starts services
checktokenmembership: Checks user token with CheckTokenMembership call
dotnet_use_suspicious_functions: Dotnet program potentially uses suspicious functions/modules
writes_data: Writes big amount of data to disk