BH12150 | Changes background/foreground colors to make macros invisible. | |
BH12157 | Changes preference variables to silent mode. | |
BH12183 | Clears event logs from local or remote computer. | |
BH12184 | Clears event logs using WMI. | |
BH12249 | Disables control panel or specific items within it. | |
BH12255 | Disables showing file extensions. | |
BH12256 | Disables showing hidden files. | |
BH12335 | Executes commands as PowerShell background jobs. | |
BH12360 | Hides a window during execution of the code. | |
BH12361 | Hides active windows. | |
BH12362 | Hides all signs of execution by using different PowerShell command line flags. | |
BH12460 | Opens an off-screen tab and starts content capture. | |
BH12467 | Prevents creating an interactive prompt for the user during execution. | |
BH12468 | Prevents loading profile scripts during execution of some commands. | |
BH12528 | Restricts add/remove programs policy using registry keys. | |
BH12561 | Sets the 'hidden file' attribute to files/directories. | |
BH12570 | Starts a hidden PowerShell session. | |
BH12575 | Starts a PowerShell session without presenting an interactive prompt to the user. | |
BH12577 | Starts an application with a minimized Command Prompt window. | |
BH12578 | Starts an application without opening a new Command Prompt window. | |
BH12612 | Tampers with command aliases. | |
BH12649 | Tampers with firewall. | |
BH12655 | Writes data to the hosts file. | |
BH12656 | Tampers with hosts registry keys. | |
BH12669 | Tampers with keyboard bindings. | |
BH12710 | Tampers with PowerShell sessions on local or remote computer. | |
BH12766 | Tampers with window transparency settings. | |
BH12767 | Tampers with Windows bootup process. | |
BH12771 | Tampers with Windows Error Reporting. | |
BH13065 | Overwrites a file to hide its contents, and deletes it. | |
BH13152 | Sets the 'hidden file' attribute to files/directories using reflection. | |
BH13238 | Writes data to the /etc/config/hosts file. | |
BH13250 | Runs in the background as a system daemon. | |
BH13269 | Contains code outside of a common screen width. | |
BH18112 | Detects common malware analysis tools. | |
BH18141 | Detects sandboxes or virtual environments. | |
BH18186 | Impersonates services related to Ad-Aware security products. | |
BH18187 | Impersonates services related to Agnitum security products. | |
BH18188 | Impersonates services related to AhnLab security products. | |
BH18189 | Impersonates services related to Avast security products. | |
BH18190 | Impersonates services related to AVG security products. | |
BH18191 | Impersonates services related to Avira security products. | |
BH18192 | Impersonates services related to BitDefender security products. | |
BH18193 | Impersonates services related to CA security products. | |
BH18194 | Impersonates services related to ClamAV security products. | |
BH18195 | Impersonates services related to common security products, firewalls or anti-virus solutions. | |
BH18196 | Impersonates services related to DrWeb security products. | |
BH18197 | Impersonates services related to ESET security products. | |
BH18198 | Impersonates services related to F-Secure security products. | |
BH18199 | Impersonates services related to G Data security products. | |
BH18200 | Impersonates services related to Ikarus security products. | |
BH18201 | Impersonates services related to K7 Computing security products. | |
BH18202 | Impersonates services related to Kaspersky security products. | |
BH18203 | Impersonates services related to Kingsoft security products. | |
BH18204 | Impersonates services related to McAfee security products. | |
BH18205 | Impersonates services related to Microsoft security products. | |
BH18206 | Impersonates services related to Norman security products. | |
BH18207 | Impersonates services related to Panda security products. | |
BH18208 | Impersonates services related to QuickHeal security products. | |
BH18209 | Impersonates services related to Rising security products. | |
BH18210 | Impersonates services related to Sophos security products. | |
BH18211 | Impersonates services related to Symantec security products. | |
BH18212 | Impersonates services related to TrendMicro security products. | |
BH18213 | Impersonates services related to ZoneLabs security products. | |