Skip to main content

Stealth

IDDescriptionSignificance / Prevalence
BH12150Changes background/foreground colors to make macros invisible.anomalous important
BH12157Changes preference variables to silent mode.uncommon
BH12183Clears event logs from local or remote computer.uncommon
BH12184Clears event logs using WMI.anomalous
BH12249Disables control panel or specific items within it.uncommon anomalous
BH12255Disables showing file extensions.uncommon anomalous
BH12256Disables showing hidden files.important uncommon
BH12335Executes commands as PowerShell background jobs.uncommon
BH12360Hides a window during execution of the code.uncommon important anomalous
BH12361Hides active windows.anomalous
BH12362Hides all signs of execution by using different PowerShell command line flags.uncommon malicious anomalous
BH12460Opens an off-screen tab and starts content capture.uncommon anomalous
BH12467Prevents creating an interactive prompt for the user during execution.uncommon
BH12468Prevents loading profile scripts during execution of some commands.uncommon
BH12528Restricts add/remove programs policy using registry keys.anomalous
BH12561Sets the 'hidden file' attribute to files/directories.uncommon anomalous
BH12570Starts a hidden PowerShell session.uncommon anomalous important
BH12575Starts a PowerShell session without presenting an interactive prompt to the user.uncommon important
BH12577Starts an application with a minimized Command Prompt window.uncommon anomalous
BH12578Starts an application without opening a new Command Prompt window.uncommon
BH12612Tampers with command aliases.uncommon
BH12649Tampers with firewall.important uncommon anomalous
BH12655Writes data to the hosts file.uncommon
BH12656Tampers with hosts registry keys.anomalous
BH12669Tampers with keyboard bindings.uncommon
BH12710Tampers with PowerShell sessions on local or remote computer.uncommon
BH12766Tampers with window transparency settings.uncommon
BH12767Tampers with Windows bootup process.important uncommon anomalous
BH12771Tampers with Windows Error Reporting.uncommon
BH13065Overwrites a file to hide its contents, and deletes it.uncommon
BH13152Sets the 'hidden file' attribute to files/directories using reflection.anomalous
BH13238Writes data to the /etc/config/hosts file.anomalous uncommon
BH13250Runs in the background as a system daemon.uncommon
BH13269Contains code outside of a common screen width. uncommon
BH13347Loads/unloads drivers.
BH13374Loads/unloads kernel modules.
BH13475Hides the AutoIt tray icon.
BH13484Turns off the command echoing feature.
BH13554Might change current history stack.
BH13596Suppresses warnings.
BH18112Detects common malware analysis tools.anomalous
BH18141Detects sandboxes or virtual environments.anomalous
BH18186Impersonates services related to Ad-Aware security products.anomalous uncommon
BH18187Impersonates services related to Agnitum security products.anomalous uncommon
BH18188Impersonates services related to AhnLab security products.anomalous uncommon
BH18189Impersonates services related to Avast security products.uncommon anomalous
BH18190Impersonates services related to AVG security products.uncommon anomalous
BH18191Impersonates services related to Avira security products.uncommon anomalous
BH18192Impersonates services related to BitDefender security products.uncommon anomalous
BH18193Impersonates services related to CA security products.anomalous uncommon
BH18194Impersonates services related to ClamAV security products.anomalous uncommon
BH18195Impersonates services related to common security products, firewalls or anti-virus solutions.uncommon
BH18196Impersonates services related to DrWeb security products.anomalous important uncommon
BH18197Impersonates services related to ESET security products.uncommon anomalous
BH18198Impersonates services related to F-Secure security products.uncommon
BH18199Impersonates services related to G Data security products.anomalous uncommon
BH18200Impersonates services related to Ikarus security products.anomalous
BH18201Impersonates services related to K7 Computing security products.anomalous uncommon
BH18202Impersonates services related to Kaspersky security products.uncommon
BH18203Impersonates services related to Kingsoft security products.uncommon anomalous
BH18204Impersonates services related to McAfee security products.uncommon anomalous
BH18205Impersonates services related to Microsoft security products.uncommon anomalous
BH18206Impersonates services related to Norman security products.uncommon anomalous
BH18207Impersonates services related to Panda security products.uncommon anomalous
BH18208Impersonates services related to QuickHeal security products.anomalous
BH18209Impersonates services related to Rising security products.uncommon anomalous
BH18210Impersonates services related to Sophos security products.uncommon anomalous
BH18211Impersonates services related to Symantec security products.uncommon anomalous
BH18212Impersonates services related to TrendMicro security products.uncommon
BH18213Impersonates services related to ZoneLabs security products.uncommon anomalous
BH19566Might enumerate number of redirects or type of last navigation.