Behaviors
List of software behaviors discovered with static code analysis.
Writes to other process' memory. (x15)
memory
Reads from other process' memory. (x15)
memory
Detects/enumerates running processes. (x5)
monitor
Terminates a process/thread. (x5)
execution
Detects presence of debuggers. (x6)
evasion
Delays execution. (x6)
execution
Tampers with module search locations. (x5)
execution
Contains a reference to a common dynamic library or an executable file. (x56)
execution
Contains reference to ntdll.dll which is NT Layer DLL. (x5)
execution