Threat Identifiers
Behavior-derived IOC feed
| Score | Category | Operation |
|---|---|---|
| 5/5 | Malicious domains | Identified command-and-control domains |
| 5/5 | Persistence behavior | Creates or modifies autorun registry keys |
| 4/5 | Credential theft | Reads browser-stored credentials |
| 4/5 | Ransomware activity | Encrypts user files with strong cipher |
| 3/5 | Defense evasion | Disables security services and tools |