Threat Database Ransomware GandCrab.FE Ransomware

GandCrab.FE Ransomware

By CagedTech in Ransomware

Threat Scorecard

Popularity Rank: 11,519
Threat Level: 100 % (High)
Infected Computers: 36
First Seen: January 16, 2013
Last Seen: June 15, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: GandCrab.FE Ransomware
Signature status: No Signature

Known Samples

MD5: 7d0cc5c40576019b7c0d097d917b1e32
SHA1: 57de1fe17cbfcedd6cdc698a2bf839bb5e38438d
SHA256: 174704E9013C87820D96FC826681F818DF4E0BB156523B47FCE4A4BF0A7F4F8D
File Size: 205.82 KB, 205824 bytes
MD5: 04553265e10d8f225602d35ffece448b
SHA1: 74be0ff8a1de890d70ed75fb97b72aadc799a2a1
SHA256: A39C232FCD63809A52A63E25B98D62286A60D5410928059E96F38808F68BFE14
File Size: 4.93 MB, 4931584 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have resources
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • 2+ executable sections
  • BINinO
  • HighEntropy
  • x86

Block Information

Total Blocks: 1
Potentially Malicious Blocks: 1
Whitelisted Blocks: 0
Unknown Blocks: 0

Visual Map

x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

Files Modified

File Attributes
c:\windows\syswow64\aapleobp.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\aapleobp.exe Generic Write,Read Attributes
c:\windows\syswow64\abhegh32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\abhegh32.exe Generic Write,Read Attributes
c:\windows\syswow64\accifl32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\accifl32.exe Generic Write,Read Attributes
c:\windows\syswow64\acjofk32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\acjofk32.exe Generic Write,Read Attributes
c:\windows\syswow64\afaebg32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\afaebg32.exe Generic Write,Read Attributes
Show More
c:\windows\syswow64\agbmiqfo.dll Generic Write,Read Attributes
c:\windows\syswow64\aidaooaa.dll Generic Write,Read Attributes
c:\windows\syswow64\ajajne32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\ajajne32.exe Generic Write,Read Attributes
c:\windows\syswow64\ambcopli.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\ambcopli.exe Generic Write,Read Attributes
c:\windows\syswow64\amneia32.dll Generic Write,Read Attributes
c:\windows\syswow64\aoffapda.dll Generic Write,Read Attributes
c:\windows\syswow64\aplfql32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\aplfql32.exe Generic Write,Read Attributes
c:\windows\syswow64\babiknpm.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\babiknpm.exe Generic Write,Read Attributes
c:\windows\syswow64\bfanie32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\bfanie32.exe Generic Write,Read Attributes
c:\windows\syswow64\bibgkp32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\bibgkp32.exe Generic Write,Read Attributes
c:\windows\syswow64\biecppgp.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\biecppgp.exe Generic Write,Read Attributes
c:\windows\syswow64\bjapiela.dll Generic Write,Read Attributes
c:\windows\syswow64\bjeidf32.dll Generic Write,Read Attributes
c:\windows\syswow64\bjkmdd32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\bjkmdd32.exe Generic Write,Read Attributes
c:\windows\syswow64\bjpfocch.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\bjpfocch.exe Generic Write,Read Attributes
c:\windows\syswow64\bnechkpc.dll Generic Write,Read Attributes
c:\windows\syswow64\bqifga32.dll Generic Write,Read Attributes
c:\windows\syswow64\calkamhb.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\calkamhb.exe Generic Write,Read Attributes
c:\windows\syswow64\cboeoe32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\cboeoe32.exe Generic Write,Read Attributes
c:\windows\syswow64\ccidbhnc.dll Generic Write,Read Attributes
c:\windows\syswow64\ccqadicb.dll Generic Write,Read Attributes
c:\windows\syswow64\cdckcgok.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\cdckcgok.exe Generic Write,Read Attributes
c:\windows\syswow64\cfmmdc32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\cfmmdc32.exe Generic Write,Read Attributes
c:\windows\syswow64\cfpjjc32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\cfpjjc32.exe Generic Write,Read Attributes
c:\windows\syswow64\cgbgpbno.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\cgbgpbno.exe Generic Write,Read Attributes
c:\windows\syswow64\cgheji32.dll Generic Write,Read Attributes
c:\windows\syswow64\cjdpjb32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\cjdpjb32.exe Generic Write,Read Attributes
c:\windows\syswow64\daancjfj.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\daancjfj.exe Generic Write,Read Attributes
c:\windows\syswow64\dbigec32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\dbigec32.exe Generic Write,Read Attributes
c:\windows\syswow64\dbkdjcbq.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\dbkdjcbq.exe Generic Write,Read Attributes
c:\windows\syswow64\dicpan32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\dicpan32.exe Generic Write,Read Attributes
c:\windows\syswow64\dielgm32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\dielgm32.exe Generic Write,Read Attributes
c:\windows\syswow64\dijfbmeh.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\dijfbmeh.exe Generic Write,Read Attributes
c:\windows\syswow64\dkcnmh32.dll Generic Write,Read Attributes
c:\windows\syswow64\dkpjgjka.dll Generic Write,Read Attributes
c:\windows\syswow64\dmceml32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\dmceml32.exe Generic Write,Read Attributes
c:\windows\syswow64\dpoecgaj.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\dpoecgaj.exe Generic Write,Read Attributes
c:\windows\syswow64\eajqiinp.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\eajqiinp.exe Generic Write,Read Attributes
c:\windows\syswow64\ecpkao32.dll Generic Write,Read Attributes
c:\windows\syswow64\edepqano.dll Generic Write,Read Attributes
c:\windows\syswow64\edfppdof.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\edfppdof.exe Generic Write,Read Attributes
c:\windows\syswow64\egifgo32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\egifgo32.exe Generic Write,Read Attributes
c:\windows\syswow64\eglnnpbn.dll Generic Write,Read Attributes
c:\windows\syswow64\egngcq32.dll Generic Write,Read Attributes
c:\windows\syswow64\eiojhjdp.dll Generic Write,Read Attributes
c:\windows\syswow64\ejeenkkk.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\ejeenkkk.exe Generic Write,Read Attributes
c:\windows\syswow64\ekgkdg32.dll Generic Write,Read Attributes
c:\windows\syswow64\emcdml32.dll Generic Write,Read Attributes
c:\windows\syswow64\emhohk32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\emhohk32.exe Generic Write,Read Attributes
c:\windows\syswow64\enjknkjl.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\enjknkjl.exe Generic Write,Read Attributes
c:\windows\syswow64\enlhcjgi.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\enlhcjgi.exe Generic Write,Read Attributes
c:\windows\syswow64\epmaee32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\epmaee32.exe Generic Write,Read Attributes
c:\windows\syswow64\faccpgfe.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\faccpgfe.exe Generic Write,Read Attributes
c:\windows\syswow64\fadkcnma.dll Generic Write,Read Attributes
c:\windows\syswow64\fcbcbpnf.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\fcbcbpnf.exe Generic Write,Read Attributes
c:\windows\syswow64\fcjibogn.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\fcjibogn.exe Generic Write,Read Attributes
c:\windows\syswow64\fdmfqc32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\fdmfqc32.exe Generic Write,Read Attributes
c:\windows\syswow64\fepahgbi.dll Generic Write,Read Attributes
c:\windows\syswow64\fhlhof32.dll Generic Write,Read Attributes
c:\windows\syswow64\fjaeji32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\fjaeji32.exe Generic Write,Read Attributes
c:\windows\syswow64\fjohdjcp.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\fjohdjcp.exe Generic Write,Read Attributes
c:\windows\syswow64\fknenmjc.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\fknenmjc.exe Generic Write,Read Attributes
c:\windows\syswow64\fncndiaa.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\fncndiaa.exe Generic Write,Read Attributes
c:\windows\syswow64\fnfkiioo.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\fnfkiioo.exe Generic Write,Read Attributes
c:\windows\syswow64\fnjddh32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\fnjddh32.exe Generic Write,Read Attributes
c:\windows\syswow64\gbmblhgd.dll Generic Write,Read Attributes
c:\windows\syswow64\gbockflh.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\gbockflh.exe Generic Write,Read Attributes
c:\windows\syswow64\gcncnn32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\gcncnn32.exe Generic Write,Read Attributes
c:\windows\syswow64\gdbibq32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\gdbibq32.exe Generic Write,Read Attributes
c:\windows\syswow64\gdfqmn32.dll Generic Write,Read Attributes
c:\windows\syswow64\gdiflb32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\gdiflb32.exe Generic Write,Read Attributes
c:\windows\syswow64\ggofoi32.dll Generic Write,Read Attributes
c:\windows\syswow64\ggohil32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\ggohil32.exe Generic Write,Read Attributes
c:\windows\syswow64\gjkhphic.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\gjkhphic.exe Generic Write,Read Attributes
c:\windows\syswow64\gkkfib32.dll Generic Write,Read Attributes
c:\windows\syswow64\gqpfac32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\gqpfac32.exe Generic Write,Read Attributes
c:\windows\syswow64\haibeoig.dll Generic Write,Read Attributes
c:\windows\syswow64\hbfileep.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\hbfileep.exe Generic Write,Read Attributes
c:\windows\syswow64\hjanqgck.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\hjanqgck.exe Generic Write,Read Attributes
c:\windows\syswow64\iibmbeoi.dll Generic Write,Read Attributes
c:\windows\syswow64\imlofd32.dll Generic Write,Read Attributes
c:\windows\syswow64\inljoanb.dll Generic Write,Read Attributes
c:\windows\syswow64\inolpa32.dll Generic Write,Read Attributes
c:\windows\syswow64\jebmpklo.dll Generic Write,Read Attributes
c:\windows\syswow64\jfobglbm.dll Generic Write,Read Attributes
c:\windows\syswow64\joojaolh.dll Generic Write,Read Attributes
c:\windows\syswow64\jpgbhben.dll Generic Write,Read Attributes
c:\windows\syswow64\khgpkfce.dll Generic Write,Read Attributes
c:\windows\syswow64\kiaibedp.dll Generic Write,Read Attributes
c:\windows\syswow64\klbgpd32.dll Generic Write,Read Attributes
c:\windows\syswow64\klbpka32.dll Generic Write,Read Attributes
c:\windows\syswow64\knpcbi32.dll Generic Write,Read Attributes
c:\windows\syswow64\lficlpen.dll Generic Write,Read Attributes
c:\windows\syswow64\lgjohdmc.dll Generic Write,Read Attributes
c:\windows\syswow64\llapni32.dll Generic Write,Read Attributes
c:\windows\syswow64\lpicdo32.dll Generic Write,Read Attributes
c:\windows\syswow64\mbodko32.dll Generic Write,Read Attributes
c:\windows\syswow64\mdiccepg.dll Generic Write,Read Attributes
c:\windows\syswow64\mepahnjc.dll Generic Write,Read Attributes
c:\windows\syswow64\mhljnc32.dll Generic Write,Read Attributes
c:\windows\syswow64\mppmajdh.dll Generic Write,Read Attributes
c:\windows\syswow64\neneaa32.dll Generic Write,Read Attributes
c:\windows\syswow64\nenfdf32.dll Generic Write,Read Attributes
c:\windows\syswow64\nhliln32.dll Generic Write,Read Attributes
c:\windows\syswow64\nikgefbg.dll Generic Write,Read Attributes
c:\windows\syswow64\npeigjqd.dll Generic Write,Read Attributes
c:\windows\syswow64\nplali32.dll Generic Write,Read Attributes
c:\windows\syswow64\odjcpb32.dll Generic Write,Read Attributes
c:\windows\syswow64\oegohg32.dll Generic Write,Read Attributes
c:\windows\syswow64\pbjifjmi.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\pbjifjmi.exe Generic Write,Read Attributes
c:\windows\syswow64\pclbemai.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\pclbemai.exe Generic Write,Read Attributes
c:\windows\syswow64\pfabhh32.dll Generic Write,Read Attributes
c:\windows\syswow64\pjkimfng.dll Generic Write,Read Attributes
c:\windows\syswow64\pmbjhb32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\pmbjhb32.exe Generic Write,Read Attributes
c:\windows\syswow64\pqpcoaqb.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\pqpcoaqb.exe Generic Write,Read Attributes
c:\windows\syswow64\qbcllidn.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\qbcllidn.exe Generic Write,Read Attributes
c:\windows\syswow64\qgfgap32.dll Generic Write,Read Attributes
c:\windows\syswow64\qikhcc32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\qikhcc32.exe Generic Write,Read Attributes
c:\windows\syswow64\qjappoch.dll Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Fhlhof32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FEACFF-FFCE-815E-A900-316290B5B738} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Ecpkao32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FEACFF-FFCE-815E-A900-316290B5B738} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Dkpjgjka.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FEACFF-FFCE-815E-A900-316290B5B738} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Ekgkdg32.dll RegNtPreCreateKey
Show More
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FEACFF-FFCE-815E-A900-316290B5B738} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Aoffapda.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FEACFF-FFCE-815E-A900-316290B5B738} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Amneia32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FEACFF-FFCE-815E-A900-316290B5B738} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Haibeoig.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FEACFF-FFCE-815E-A900-316290B5B738} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Nplali32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FEACFF-FFCE-815E-A900-316290B5B738} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Mhljnc32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FEACFF-FFCE-815E-A900-316290B5B738} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Aidaooaa.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FEACFF-FFCE-815E-A900-316290B5B738} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Oegohg32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FEACFF-FFCE-815E-A900-316290B5B738} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Qjappoch.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FEACFF-FFCE-815E-A900-316290B5B738} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Fadkcnma.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FEACFF-FFCE-815E-A900-316290B5B738} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Edepqano.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FEACFF-FFCE-815E-A900-316290B5B738} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Khgpkfce.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FEACFF-FFCE-815E-A900-316290B5B738} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Gbmblhgd.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FEACFF-FFCE-815E-A900-316290B5B738} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Bjeidf32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FEACFF-FFCE-815E-A900-316290B5B738} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Lgjohdmc.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FEACFF-FFCE-815E-A900-316290B5B738} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Odjcpb32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FEACFF-FFCE-815E-A900-316290B5B738} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Lficlpen.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FEACFF-FFCE-815E-A900-316290B5B738} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Ccqadicb.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FEACFF-FFCE-815E-A900-316290B5B738} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Dkcnmh32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FEACFF-FFCE-815E-A900-316290B5B738} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Bjapiela.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FEACFF-FFCE-815E-A900-316290B5B738} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Klbpka32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FEACFF-FFCE-815E-A900-316290B5B738} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Fepahgbi.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FEACFF-FFCE-815E-A900-316290B5B738} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Qgfgap32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FEACFF-FFCE-815E-A900-316290B5B738} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Kiaibedp.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FEACFF-FFCE-815E-A900-316290B5B738} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Emcdml32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FEACFF-FFCE-815E-A900-316290B5B738} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Eglnnpbn.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FEACFF-FFCE-815E-A900-316290B5B738} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Gkkfib32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FEACFF-FFCE-815E-A900-316290B5B738} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Joojaolh.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FEACFF-FFCE-815E-A900-316290B5B738} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Lpicdo32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FEACFF-FFCE-815E-A900-316290B5B738} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Ccidbhnc.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FEACFF-FFCE-815E-A900-316290B5B738} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Pjkimfng.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FEACFF-FFCE-815E-A900-316290B5B738} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Jebmpklo.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FEACFF-FFCE-815E-A900-316290B5B738} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Egngcq32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FEACFF-FFCE-815E-A900-316290B5B738} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Mepahnjc.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Llapni32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Nhliln32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Agbmiqfo.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Inolpa32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Mbodko32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Inljoanb.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Neneaa32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Jfobglbm.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Knpcbi32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Ggofoi32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Iibmbeoi.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Nikgefbg.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Bqifga32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Nenfdf32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Gdfqmn32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Eiojhjdp.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Bnechkpc.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Mdiccepg.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Klbgpd32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Npeigjqd.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Cgheji32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Imlofd32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Mppmajdh.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Pfabhh32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Jpgbhben.dll RegNtPreCreateKey

Windows API Usage

Category API
Process Manipulation Evasion
  • NtUnmapViewOfSection

Trending

Most Viewed

Loading...