Skip to main content

Anomaly

IDDescriptionSignificance / Prevalence
BH12142Attempts to brute-force passwords.
BH12159Changes printing mode to large bitmap.
BH12169Changes the way PowerShell console reads input.
BH12185Contains blocks used in SHA-1 collision attacks.
BH12188Calls a function through the Execute() function, commonly used for obfuscation.
BH12189Contains executable filenames resembling the Service Host Process executable.
BH12190Contains executable filenames resembling the Windows Explorer executable.
BH12192Contains double encoded hexadecimal representation of the BinaryToString() function, commonly used for obfuscation.
BH12193Contains cryptocurrency wallet addresses associated with ransomware.
BH12366Imports command aliases from file.
BH12405Loads a trusted execution enclave with data.
BH12410Manipulates default macro code in the normal template document.
BH12411Manipulates macro code in the currently active document.
BH12412Manipulates macro code in the currently active workbook.
BH12770Tampers with Windows Deployment Services.
BH12825Removes a trusted execution enclave from a process.
BH12851Suppresses ILDASM disassembly.
BH13249Contains a list of default passwords for various services and devices.
BH13302Contains prefix trie tables used for string obfuscation in the XZ Utils software compromise.
BH15156Decrypts data within a trusted execution enclave.
BH15184Uses unusually long variable names, commonly used for obfuscation.
BH15218Contains the RLO (right-to-left override) Unicode character, commonly used with bidirectional text.
BH15219Contains the LRI (left-to-right isolate) Unicode character, commonly used with bidirectional text.
BH15220Contains the PDI (pop directional isolate) Unicode character, commonly used with bidirectional text.
BH15221Contains the LRE (left-to-right embedding) Unicode character, commonly used with bidirectional text.
BH15222Contains the RLE (right-to-left embedding) Unicode character, commonly used with bidirectional text.
BH15223Contains the PDF (pop directional formatting) Unicode character, commonly used with bidirectional text.
BH15224Contains the LRO (left-to-right override) Unicode character, commonly used with bidirectional text.
BH15225Contains the RLI (right-to-left isolate) Unicode character, commonly used with bidirectional text.
BH15226Contains the FSI (first strong isolate) Unicode character, commonly used with bidirectional text.
BH15227Contains the ZWSP (zero width space) Unicode character.
BH15228Contains the ZWNJ (zero width non-joiner) Unicode character.
BH16138Contains e-mail addresses associated with ransomware.
BH16139Contains domains associated with ransomware.
BH16319Contains Base64-encoded URLs.
BH17117Collects credit card cardholder's name from Track 1 data.
BH17118Collects credit card information.
BH17119Collects credit card PAN number from Track 1 data.
BH17120Collects credit card PAN number from Track 2 data.
BH17121Collects credit card service code and discretionary data from Track 1 or Track 2 data.
BH17122Collects information about credit card management devices.
BH17123Contains a regex that's commonly used to validate American Express credit card numbers.
BH17124Contains a regex that's commonly used to validate BCGlobal credit card numbers.
BH17125Contains a regex that's commonly used to validate credit card cardholder's name from Track 1 data.
BH17126Contains a regex that's commonly used to validate credit card PAN numbers from Track 1 data.
BH17127Contains a regex that's commonly used to validate credit card PAN numbers from Track 2 data.
BH17128Contains a regex that's commonly used to validate credit card service code and discretionary data from Track 1 or Track 2 data.
BH17129Contains a regex that's commonly used to validate Diners Club credit card numbers.
BH17130Contains a regex that's commonly used to validate Discover credit card numbers.
BH17131Contains a regex that's commonly used to validate Insta Payment credit card numbers.
BH17132Contains a regex that's commonly used to validate JCB credit card numbers.
BH17133Contains a regex that's commonly used to validate Laser credit card numbers.
BH17134Contains a regex that's commonly used to validate Maestro credit card numbers.
BH17135Contains a regex that's commonly used to validate Mastercard credit card numbers.
BH17136Contains a regex that's commonly used to validate Solo credit card numbers.
BH17137Contains a regex that's commonly used to validate Switch credit card numbers.
BH17138Contains a regex that's commonly used to validate the type or name of credit card management devices.
BH17139Contains a regex that's commonly used to validate Union Pay credit card numbers.
BH17140Contains a regex that's commonly used to validate Visa credit card numbers.
BH17143Contains format strings related to Bitcoin prices.
BH17176Reads data from icon stream object.
BH17436Contains regular expressions used to detect presence of common crypto tokens.
BH20169Uses PowerSploit/Empire command to cause the blue screen upon exiting PowerShell.
BH20243Uses PowerSploit/Empire command to overwrite the Master Boot Record.