-
Notifications
You must be signed in to change notification settings - Fork 207
Open
Labels
false positiveFalse positive rule hitFalse positive rule hit
Description
Function: 0x45B8DB
What it does: The function calls GetProcAddress for DeleteProcThreadAttributeList and CreateProcess.
Why it matched: capa matched the regex del on the API string DeleteProcThread.... The function creates a process with a specified parent (PID Spoofing), it does not delete itself.
Metadata
Metadata
Assignees
Labels
false positiveFalse positive rule hitFalse positive rule hit