@@ -16,11 +16,27 @@ rule:
16
16
examples :
17
17
- Practical Malware Analysis Lab 03-03.exe_:0x4010EA
18
18
features :
19
- - and :
20
- - or :
21
- - number : 0x08000004 = CREATE_NO_WINDOW | CREATE_SUSPENDED
22
- - number : 4 = CREATE_SUSPENDED
23
- - number : 2 = DEBUG_ONLY_THIS_PROCESS
24
- - or :
25
- - api : kernel32.CreateProcess
26
- - api : advapi32.CreateProcessAsUser
19
+ - or :
20
+ - and :
21
+ - or :
22
+ - number : 0x08000004 = CREATE_NO_WINDOW | CREATE_SUSPENDED
23
+ - number : 0x800000C = CREATE_SUSPENDED | DETACHED_PROCESS | CREATE_NO_WINDOW
24
+ - number : 4 = CREATE_SUSPENDED
25
+ - number : 2 = DEBUG_ONLY_THIS_PROCESS
26
+ - or :
27
+ - api : kernel32.CreateProcess
28
+ - api : kernel32.CreateProcessInternal
29
+ - api : advapi32.CreateProcessAsUser
30
+ - api : advapi32.CreateProcessWithLogon
31
+ - api : advapi32.CreateProcessWithToken
32
+ - and :
33
+ - or :
34
+ - number : 0x10 = PROCESS_CREATE_FLAGS_CREATE_SUSPENDED
35
+ - number : 0x2000010 = PROCESS_CREATE_FLAGS_CREATE_SUSPENDED | PROCESS_CREATE_FLAGS_NO_WINDOW
36
+ - number : 0x11 = PROCESS_CREATE_FLAGS_CREATE_SUSPENDED | PROCESS_CREATE_FLAGS_BREAKAWAY
37
+ - or :
38
+ - api : ntdll.NtCreateProcessEx
39
+ - api : ZwCreateProcessEx
40
+ - api : ntdll.NtCreateUserProcess
41
+ - api : ntdll.ZwCreateUserProcess
42
+ - api : ntdll.RtlCreateUserProcess
0 commit comments