Behaviors
List of software behaviors discovered with static code analysis.
Retrieves the name of the user associated with the process. (x1)
search
Calculates the SHA-256 hash of data. (x1)
file
Detects presence of debuggers. (x2)
evasion
Contains reference to bcrypt.dll which is Windows Cryptographic Primitives Library (Wow64). (x1)
execution
Contains reference to ntdll.dll which is NT Layer DLL. (x1)
execution
Contains reference to kernel32.dll which is Windows NT BASE API Client DLL. (x1)
execution
Contains reference to advapi32.dll which is Advanced Windows 32 Base API. (x1)
execution