← All detection heuristics · Shellcode
critical
SC_STR_WRITEPROCESSMEMORY
What it means
String 'WriteProcessMemory' found in file bytes.
Why it fires
WriteProcessMemory writes bytes into another process. Malware uses it with VirtualAllocEx and CreateRemoteThread for process injection.
Other Shellcode heuristics
SC_STR_CREATEREMOTETHREAD SC_MSF_BIND SC_MSF_REVERSE SC_MSF_C2 SC_STR_URLDOWNLOAD SC_XOR_ENCODED SC_STR_CREATEPROCESS SC_EGG_HUNTER SC_STR_GETPROCADDRESS SC_HEAP_SPRAY SC_STR_LOADLIBRARY SC_API_HASH_RESOLVER SC_PEB_ACCESS_X64 SC_PEB_ACCESS SC_STR_POWERSHELL SC_STR_SHELLEXEC SC_STR_WINEXEC SC_STR_WSCRIPT SC_XOR_DECODER SC_XOR_DECODED_NETWORK_CONFIG SC_STR_BITSADMIN SC_STR_CERTUTIL SC_STR_CMD SC_STR_MSHTA