Skip to main content

Stealth

IDDescriptionSignificance / Prevalence
BH12150Changes background/foreground colors to make macros invisible.
BH12157Changes preference variables to silent mode.
BH12183Clears event logs from local or remote computer.
BH12184Clears event logs using WMI.
BH12249Disables control panel or specific items within it.
BH12255Disables showing file extensions.
BH12256Disables showing hidden files.
BH12335Executes commands as PowerShell background jobs.
BH12360Hides a window during execution of the code.
BH12361Hides active windows.
BH12362Hides all signs of execution by using different PowerShell command line flags.
BH12460Opens an off-screen tab and starts content capture.
BH12467Prevents creating an interactive prompt for the user during execution.
BH12468Prevents loading profile scripts during execution of some commands.
BH12528Restricts add/remove programs policy using registry keys.
BH12561Sets the 'hidden file' attribute to files/directories.
BH12570Starts a hidden PowerShell session.
BH12575Starts a PowerShell session without presenting an interactive prompt to the user.
BH12577Starts an application with a minimized Command Prompt window.
BH12578Starts an application without opening a new Command Prompt window.
BH12612Tampers with command aliases.
BH12649Tampers with firewall.
BH12655Writes data to the hosts file.
BH12656Tampers with hosts registry keys.
BH12669Tampers with keyboard bindings.
BH12710Tampers with PowerShell sessions on local or remote computer.
BH12766Tampers with window transparency settings.
BH12767Tampers with Windows bootup process.
BH12771Tampers with Windows Error Reporting.
BH13065Overwrites a file to hide its contents, and deletes it.
BH13152Sets the 'hidden file' attribute to files/directories using reflection.
BH13238Writes data to the /etc/config/hosts file.
BH13250Runs in the background as a system daemon.
BH13269Contains code outside of a common screen width.
BH18112Detects common malware analysis tools.
BH18141Detects sandboxes or virtual environments.
BH18186Impersonates services related to Ad-Aware security products.
BH18187Impersonates services related to Agnitum security products.
BH18188Impersonates services related to AhnLab security products.
BH18189Impersonates services related to Avast security products.
BH18190Impersonates services related to AVG security products.
BH18191Impersonates services related to Avira security products.
BH18192Impersonates services related to BitDefender security products.
BH18193Impersonates services related to CA security products.
BH18194Impersonates services related to ClamAV security products.
BH18195Impersonates services related to common security products, firewalls or anti-virus solutions.
BH18196Impersonates services related to DrWeb security products.
BH18197Impersonates services related to ESET security products.
BH18198Impersonates services related to F-Secure security products.
BH18199Impersonates services related to G Data security products.
BH18200Impersonates services related to Ikarus security products.
BH18201Impersonates services related to K7 Computing security products.
BH18202Impersonates services related to Kaspersky security products.
BH18203Impersonates services related to Kingsoft security products.
BH18204Impersonates services related to McAfee security products.
BH18205Impersonates services related to Microsoft security products.
BH18206Impersonates services related to Norman security products.
BH18207Impersonates services related to Panda security products.
BH18208Impersonates services related to QuickHeal security products.
BH18209Impersonates services related to Rising security products.
BH18210Impersonates services related to Sophos security products.
BH18211Impersonates services related to Symantec security products.
BH18212Impersonates services related to TrendMicro security products.
BH18213Impersonates services related to ZoneLabs security products.