Skip to main content

Evasion

IDDescriptionSignificance / Prevalence
BH12163Changes settings that enable remote users to run commands on the local computer.uncommon
BH12253Disables Office's macro virus protection capabilities.anomalous important uncommon
BH12281Disables the Network Inspection service (NIS).anomalous
BH12296Disables the Windows Event Log service.anomalous
BH12297Disables the Windows Firewall service.anomalous
BH12302Disables the Windows Update service.anomalous uncommon
BH12303Disables Windows Patchguard.anomalous
BH12425Modifies handler for F11 function key, used to access the macro editor.anomalous
BH12426Modifies handler for F8 function key, used to open the macro dialog box.anomalous
BH12462Overwrites free space and prevents file recovery.anomalous
BH12469Prevents the user from aborting the batch execution.anomalous
BH12574Starts a PowerShell session with execution policy set to 'bypass'.uncommon
BH12619Tampers with debugger.uncommon
BH12805Detects presence of debuggers.
BH12813Uses JavaScript debugger.anomalous
BH12814Uses ping utility to delay the execution of the application, commonly used as an anti-emulation and anti-tracing technique.uncommon anomalous
BH12816Uses VBA anti-emulation techniques.anomalous uncommon
BH13260Uses debugging methods.uncommon
BH13549Might start profiling.
BH14101Attempts to evade UAC by abusing AppInfo command line parser.anomalous important
BH14102Attempts to evade UAC by abusing COM entry hijack.anomalous important
BH14103Attempts to evade UAC by abusing GetLongPathNameW behavior in Application Information Service.anomalous important
BH14104Attempts to evade UAC by combining NTFS reparse point and DLL hijack UAC bypass.anomalous important
BH14105Attempts to evade UAC by controlling App Path registry key data.anomalous important
BH14106Attempts to evade UAC by DLL hijack of SystemProperties commands.anomalous important
BH14107Attempts to evade UAC by hijacking mscfile shell command.anomalous important
BH14108Attempts to evade UAC by manipulating current user environment variables.anomalous important
BH14109Attempts to evade UAC by obtaining the token of an auto-elevated process.anomalous important uncommon
BH14110Attempts to evade UAC by overwriting ms-settings shell command.anomalous important
BH14111Attempts to evade UAC by reusing token from UIAccess application.anomalous important
BH14112Attempts to evade UAC by tricking Clean Manager.anomalous important
BH14113Attempts to evade UAC by using AccessibilityCplAdmin elevated launch.anomalous important
BH14114Attempts to evade UAC by using BitlockerWizardElev race condition.anomalous important
BH14115Attempts to evade UAC by using a Cerber-style UAC bypass.anomalous important
BH14116Attempts to evade UAC by using CMLuaUtil interface.anomalous important
BH14117Attempts to evade UAC by using ColorDataProxy/CCMLuaUtil undocumented COM interfaces.anomalous important
BH14118Attempts to evade UAC by using COM handlers hijacking.anomalous important
BH14119Attempts to evade UAC by using COR profiler.anomalous important
BH14120Attempts to evade UAC by using CreateNewLink autoelevated interface.anomalous important
BH14121Attempts to evade UAC by using DiskCleanup environment variable.anomalous important
BH14122Attempts to evade UAC by using EditionUpgradeManager autoelevated interface.anomalous important
BH14123Attempts to evade UAC by using FwCplLua undocumented COM interface.anomalous important
BH14124Attempts to evade UAC by using IDateTimeStateWriter COM interface.anomalous important
BH14125Attempts to evade UAC by using IsolatedCommand UAC bypass.anomalous important
BH14126Attempts to evade UAC by using Microsoft Management Console via ALPC.anomalous important
BH14127Attempts to evade UAC by using self-defined SystemRoot environment.anomalous important
BH14128Attempts to evade UAC by using SLUI elevated launch.anomalous important
BH14129Attempts to evade UAC by using SPPLUAObject COM interface.anomalous important
BH14130Attempts to evade UAC by using uiAccess UAC bypass.anomalous important
BH14131Attempts to evade UAC by using undocumented IARPUninstallStringLauncher interface.anomalous important
BH14132Attempts to evade UAC by using whitelisted InfDefaultInstall interface.anomalous important
BH14133Attempts to evade UAC by using WOW64 logger DLL.anomalous important
BH14134Attempts to evade UAC using AppInfo AutoApproveEXEList UAC bypass.anomalous important
BH14135Attempts to evade UAC using AppInfo Manifest UAC bypass.anomalous important
BH14136Attempts to evade UAC using AppInfo whitelisting model UAC bypass.anomalous important
BH14137Attempts to evade UAC using Application Verifier UAC bypass.anomalous important
BH14138Attempts to evade UAC using AutoElevate UAC bypass.anomalous important
BH14139Attempts to evade UAC using Deployment Image Servicing and Management UAC bypass.anomalous important
BH14140Attempts to evade UAC using generic autoelevation UAC bypass.anomalous important
BH14141Attempts to evade UAC using "Get Windows" marketing package UAC bypass.anomalous important
BH14142Attempts to evade UAC using IIS InetMgr UAC bypass.anomalous important
BH14143Attempts to evade UAC using Microsoft Management Console UAC bypass.anomalous important
BH14144Attempts to evade UAC using OOBE AppInfo whitelisting UAC bypass.anomalous important
BH14145Attempts to evade UAC using shim patching UAC bypass.anomalous important
BH14146Attempts to evade UAC using shim RedirectEXE UAC bypass.anomalous important
BH14147Attempts to evade UAC using Simda UAC bypass.anomalous important
BH14148Attempts to evade UAC using SXS Local Redirect UAC bypass.anomalous important
BH14149Attempts to evade UAC using Wusa Cabinet UAC bypass.anomalous important
BH15185The file contains push-obfuscated API strings.uncommon
BH15283Uses hex-obfuscated module import directive.uncommon anomalous important
BH15286Uses hex-obfuscated import directive of external modules.uncommon anomalous
BH15356Contains an uninterrupted sequence of Unicode-escaped characters.
BH15357Contains Unicode-escaped characters that are otherwise printable.
BH16101Contains potentially deceptive links. uncommon
BH18101Detects Ad-Aware related security products.uncommon anomalous
BH18102Detects Agnitum related security products.uncommon anomalous
BH18103Detects AhnLab related security products.anomalous uncommon
BH18104Detects Anubis sandbox related virtualized environments.uncommon
BH18105Detects Avast related security products.uncommon anomalous
BH18106Detects AVG related security products.uncommon anomalous
BH18107Detects Avira related security products.uncommon anomalous
BH18108Detects BitDefender related security products.uncommon anomalous
BH18109Detects Bochs emulator related virtualized environments.anomalous uncommon
BH18110Detects CA related security products.uncommon anomalous
BH18111Detects CheckPoint related security products.anomalous
BH18113Detects common security products, firewalls or anti-virus solutions.uncommon
BH18114Detects Comodo related security products.uncommon anomalous
BH18115Detects Cuckoo sandbox related virtualized environments.anomalous
BH18116Detects CW sandbox related virtualized environments.anomalous
BH18117Detects ESET related security products.uncommon anomalous
BH18118Detects F-Secure related security products.uncommon
BH18119Detects Fortinet related security products.anomalous
BH18120Detects Fortinet sandbox related virtualized environments.anomalous
BH18121Detects G Data related security products.uncommon anomalous
BH18122Detects generic virtualized environments.uncommon
BH18124Detects installed security products using WMI.uncommon anomalous
BH18125Detects JoeBox sandbox related virtualized environments.anomalous uncommon
BH18126Detects K7 Computing related security products.uncommon anomalous
BH18127Detects Kaspersky related security products.important uncommon
BH18128Detects Kingsoft related security products.uncommon anomalous
BH18129Detects KVM related virtualized environments.uncommon
BH18130Detects McAfee related security products.uncommon anomalous
BH18131Detects Microsoft Hyper-V related virtualized environments.uncommon
BH18132Detects Microsoft related security products.uncommon anomalous
BH18133Detects Microsoft VirtualPC related virtualized environments.uncommon anomalous
BH18134Detects Norman related security products.uncommon anomalous
BH18135Detects Panda related security products.uncommon anomalous
BH18136Detects Parallels related virtualized environments.uncommon anomalous
BH18137Detects PCTools related security products.uncommon anomalous
BH18138Detects QEMU related virtualized environments.uncommon anomalous
BH18139Detects QuickHeal related security products.anomalous
BH18140Detects Rising related security products.uncommon anomalous
BH18142Detects Sandboxie sandbox related virtualized environments.uncommon anomalous
BH18143Detects Sophos related security products.uncommon anomalous
BH18144Detects Sunbelt related security products.anomalous
BH18145Detects SunBelt sandbox related virtualized environments.uncommon anomalous
BH18146Detects Sygate related security products.anomalous
BH18147Detects Symantec related security products.uncommon anomalous
BH18148Detects TrendMicro related security products.uncommon
BH18149Detects VirtualBox related virtualized environments.uncommon
BH18150Detects VMWare related virtualized environments.uncommon
BH18151Detects Webroot related security products.uncommon anomalous
BH18152Detects Wine related virtualized environments.uncommon anomalous
BH18153Detects Xen related virtualized environments.uncommon
BH18154Detects ZoneLabs related security products.uncommon anomalous
BH18155Disables services related to Ad-Aware security products.anomalous important uncommon
BH18156Disables services related to Agnitum security products.anomalous uncommon
BH18157Disables services related to AhnLab security products.anomalous important uncommon
BH18158Disables services related to Avast security products.important uncommon anomalous
BH18159Disables services related to AVG security products.important uncommon anomalous
BH18160Disables services related to Avira security products.important uncommon anomalous
BH18161Disables services related to BitDefender security products.important uncommon anomalous
BH18162Disables services related to CA security products.anomalous important uncommon
BH18163Disables services related to ClamAV security products.anomalous important uncommon
BH18164Disables services related to common security products, firewalls or anti-virus solutions.uncommon
BH18165Disables services related to DrWeb security products.anomalous uncommon
BH18166Disables services related to Emsisoft security products.anomalous important
BH18167Disables services related to ESET security products.important uncommon anomalous
BH18168Disables services related to F-Secure security products.important uncommon
BH18169Disables services related to G Data security products.anomalous important uncommon
BH18170Disables services related to Ikarus security products.anomalous important
BH18171Disables services related to K7 Computing security products.anomalous important uncommon
BH18172Disables services related to Kaspersky security products.important uncommon
BH18173Disables services related to Kingsoft security products.uncommon anomalous
BH18174Disables services related to Malwarebytes security products.anomalous important
BH18175Disables services related to McAfee security products.important uncommon anomalous
BH18176Disables services related to Microsoft security products.important uncommon anomalous
BH18177Disables services related to Norman security products.important uncommon anomalous
BH18178Disables services related to Panda security products.important uncommon anomalous
BH18179Disables services related to QuickHeal security products.anomalous important
BH18180Disables services related to Rising security products.important uncommon anomalous
BH18181Disables services related to Sophos security products.important uncommon anomalous
BH18182Disables services related to Symantec security products.important uncommon anomalous
BH18183Disables services related to TrendMicro security products.uncommon
BH18184Disables services related to Windows Defender.anomalous
BH18185Disables services related to ZoneLabs security products.important uncommon anomalous
BH18214Tampers with services related to Ad-Aware security products.anomalous important uncommon
BH18215Tampers with services related to Agnitum security products.anomalous important uncommon
BH18216Tampers with services related to AhnLab security products.anomalous important uncommon
BH18217Tampers with services related to Avast security products.important uncommon anomalous
BH18218Tampers with services related to AVG security products.important uncommon anomalous
BH18219Tampers with services related to Avira security products.important uncommon anomalous
BH18220Tampers with services related to BitDefender security products.important uncommon anomalous
BH18221Tampers with services related to CA security products.important uncommon anomalous
BH18222Tampers with services related to ClamAV security products.anomalous important uncommon
BH18223Tampers with services related to common security products, firewalls or anti-virus solutions.important uncommon
BH18224Tampers with services related to DrWeb security products.anomalous important uncommon
BH18225Tampers with services related to ESET security products.important uncommon anomalous
BH18226Tampers with services related to F-Secure security products.important uncommon
BH18227Tampers with services related to G Data security products.anomalous important uncommon
BH18228Tampers with services related to Ikarus security products.anomalous important
BH18229Tampers with services related to K7 Computing security products.anomalous important uncommon
BH18230Tampers with services related to Kaspersky security products.important uncommon
BH18231Tampers with services related to Kingsoft security products.important uncommon anomalous
BH18232Tampers with services related to McAfee security products.important uncommon
BH18233Tampers with services related to Microsoft security products.important uncommon anomalous
BH18234Tampers with services related to Norman security products.important uncommon anomalous
BH18235Tampers with services related to Panda security products.important uncommon anomalous
BH18236Tampers with services related to QuickHeal security products.anomalous important
BH18237Tampers with services related to Rising security products.important uncommon anomalous
BH18238Tampers with services related to Sophos security products.important uncommon anomalous
BH18239Tampers with services related to Symantec security products.important uncommon anomalous
BH18240Tampers with services related to TrendMicro security products.important uncommon
BH18241Tampers with services related to ZoneLabs security products.important uncommon anomalous
BH18247Checks the AppArmor status.uncommon anomalous
BH18248Disables AppArmor.anomalous
BH18249Contains strings commonly used for detecting VMs.uncommon anomalous
BH18250Detects common security products.
BH18251Detects ClamAV related security products.
BH18252Detects DrWeb related security products.
BH19123Enumerates breakpoints that are set in the current session.uncommon
BH19147Enumerates debugger breakpoints.anomalous
BH19375Gets preferences for the Windows Defender scans and updates.uncommon
BH19415Gets the status of antimalware software on the computer.uncommon
BH19565Might enumerate time related performance information.
BH20104Uses a Nishang command to bypass UAC using several known methods.anomalous malicious uncommon
BH20105Uses a Nishang command to bypass Windows Antimalware Scan Interface.anomalous malicious
BH20121Uses a Nishang command to detect whether it is in a known virtual machine.anomalous malicious uncommon
BH20236Uses PowerSploit/Empire command to locate single byte AV signatures.anomalous malicious uncommon
BH20247Uses PowerSploit/Empire command to perform a UAC bypass attack by duplicating a High Integrity security access token.anomalous malicious
BH20248Uses PowerSploit/Empire command to perform a UAC bypass attack by abusing the lack of an embedded manifest in wscript.exe.anomalous malicious uncommon
BH20249Uses PowerSploit/Empire command to perform a UAC bypass attack by utilizing the trusted publisher certificate through process injection.anomalous malicious uncommon