Behaviors
List of software behaviors discovered with static code analysis.
Contains URLs that link to interesting file formats. (x1)
network
Contains IP addresses. (x4)
network
Decrypts data using the Windows Data Protection API. (x3)
execution
Contains URLs. (x1)
network
Contains patterns identifying the constants related to the SHA-256 hash function, from the SHA-2 hash family. (x6)
signature
Contains reference to advapi32.dll which is Advanced Windows 32 Base API. (x3)
execution
Contains reference to shell32.dll which is Windows Shell Common Dll. (x3)
execution
Contains reference to ntdll.dll which is NT Layer DLL. (x3)
execution
Contains reference to ole32.dll which is Microsoft OLE for Windows. (x3)
execution
Contains a reference to a common dynamic library or an executable file. (x93)
execution