Above we can see that the last frame on our call stack is our `MySleep` callback.
47
-
One can wonder ifthat immediately brings opportunities for IOCs hunting for threads having call stacks not unwinding into following twocommonlyexpected thread entry points within system libraries:
47
+
One can wonder doesit immediately brings opportunities new IOCs?Huntingrulescanlook for threads having call stacks not unwinding into following expected thread entry pointslocated within system libraries:
48
48
49
49
```
50
50
kernel32!BaseThreadInitThunk+0x14
51
51
ntdll!RtlUserThreadStart+0x21
52
52
```
53
53
54
-
However the call stack of spoofed thread may look rather at first, a brief examination of my system shown, that there are other threads havingcallstacksnot unwinding to the above handlers as well:
54
+
However the call stack of thespoofed thread may look ratherodd at first, a brief examination of my system shown, that there are other threads not unwinding to the above entrypoints as well: