PUP.BadJoke.PG

The detection of PUP.BadJoke.PG indicates that your system has been compromised by a potentially unwanted program (PUP). This type of threat is designed to disrupt your computer's normal functioning and may expose you to various risks, including data breaches, unwanted advertisements, and decreased system performance. It is essential to address this issue promptly to prevent further damage and potential harm.

What Is PUP.BadJoke.PG?

PUP.BadJoke.PG is a type of malicious software that is not necessarily a virus but can still cause significant problems on your computer. It may have been installed intentionally or unintentionally, often bundled with other software or downloaded from untrusted sources. PUPs like PUP.BadJoke.PG can be challenging to remove, as they may have created multiple entries in your system's registry, started services, or even modified system files.

How PUP.BadJoke.PG Operates

Once installed, PUP.BadJoke.PG may begin to display unwanted advertisements, collect your browsing data, or even install additional malicious software. It may also attempt to connect to remote servers to download updates or receive instructions from its creators. In some cases, PUPs can be used to distribute more severe threats, such as ransomware or Trojans, making it crucial to remove them as soon as possible.

Symptoms of Infection

Systems infected with PUP.BadJoke.PG may exhibit various symptoms, including slower performance, increased pop-up advertisements, or unexpected changes to browser settings. You may also notice that your browser's homepage or default search engine has been altered without your consent. In some cases, you might experience frequent system crashes or freezes, indicating that the PUP is interfering with your computer's normal operation.

  • Unwanted advertisements or pop-ups
  • Changes to browser settings or homepage
  • Slower system performance
  • Increased risk of data breaches or identity theft

How to Remove PUP.BadJoke.PG

  1. Boot your computer in Safe Mode with Networking to prevent the PUP from loading and interfering with the removal process.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and detect any associated files or registry entries.
  3. Uninstall any suspicious programs or software that may be related to the PUP.BadJoke.PG infection.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any unwanted extensions or add-ons.
  5. Reboot your computer and perform another scan to ensure that all remnants of the PUP have been removed.

Conclusion

Removing PUP.BadJoke.PG from your system requires careful attention to detail and a thorough understanding of how PUPs operate. By following the steps outlined above and using reputable anti-malware tools, you can effectively eliminate this threat and restore your computer's normal functioning. Remember to always be cautious when downloading software or clicking on links from untrusted sources, as these are common ways for PUPs to infect systems. Regularly updating your operating system, browser, and security software can also help prevent similar infections in the future.

Analysis Report

General information

Family Name: PUP.BadJoke.PG
Signature status: No Signature

Known Samples

MD5: 3f88af2ff6c929380294ea6b406de9aa
SHA1: f95a0fa62b803094ce969b37364e3aa1d8079c52
SHA256: 7A8BA863B86526B5AA7EB5EFEA18415162AEF77A8CB1F2C328BF42EDD3853B39
File Size: 7.78 MB, 7776680 bytes
MD5: f3319e077821a570a0192f3dad703296
SHA1: a16327b694085a4dec773938a38bc549d7193c6f
SHA256: F36AE1E772B4A7E4A54803ABC23EA5800DC68804079A41799C1EF3E71B09230D
File Size: 7.25 MB, 7246723 bytes
MD5: 7671e25ff8f1b8e884fd35bdc2b5ffcf
SHA1: 481c6db2efb156aa46d99b02be519a362a43a6bc
SHA256: 3B0B01232BDE3E033B4E2FC05261E5BB1A73CEE7238075CDEF6A83649F1DB583
File Size: 9.21 MB, 9214013 bytes
MD5: 2d480b6a0e67fc2eabd57f7cc1ff5e1f
SHA1: 9b7e9800004beb513aeae1499d7dc6956d128458
SHA256: 2CFE31839810AAE617E8E1CDDA045670FDDDAEB59CD50C3FC4AECBAF175F046A
File Size: 7.66 MB, 7658984 bytes
MD5: 5c6f46b52b07f2255022bdf6e524190e
SHA1: 78b3deabff41b20af47c23c6ed91739e111405ea
SHA256: 92121DBBD29B667A520DBE2058303E07FF383976CCB8AB360656F3A5AA6E8DB0
File Size: 5.65 MB, 5649700 bytes
Show More
MD5: d22d4c1e29a7a80a8c902fa0c94bbebb
SHA1: 394625c48cf2cb000cdaeb26a3171ebab30f2d58
SHA256: D535C15D6910F99F2C2F1C837567C14A57DD601FDCED6716C97F0910BD50D195
File Size: 6.70 MB, 6698774 bytes
MD5: 3924ad878bd22fdfe5623df44cd9ec65
SHA1: ba857ebd5dc755f6a694400e49fa839573f5b202
SHA256: 67621B75460DA03AC84F932B34818424A3A2368C73AB24F37824FF8A8E05B454
File Size: 2.06 MB, 2063692 bytes
MD5: 4319345dedfe50b7efea004e0123f831
SHA1: 97c0366a31b1cdc0548170d33024c6483fc748e3
SHA256: 50A739948F01ABD7B5901FBFA568426ABA97F9DE082FB83F4C786E9079E5F392
File Size: 1.95 MB, 1948288 bytes
MD5: f8cdb901add99c406115074afbf44044
SHA1: 709f42ab8859fa6a55b0413fbc20e328a77d9fc2
SHA256: 68CAEB24126EB199C13667DAD5522880172BE7C5F2BFF05E787E5334A5BDAEBE
File Size: 8.30 MB, 8297043 bytes
MD5: 31af39022eaafea04ad3729749fc86b2
SHA1: 7df3aab87c2dadd52bfcd81ea8104cca681daf72
SHA256: 9E95658577E7065A3C387038D1654C3A1E807F308E8D05FD23DE562C07CD9698
File Size: 3.81 MB, 3805942 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name
  • Microsoft Corporation
  • OOO Sberbank-Service
File Description
  • EMS
  • wuapihost
File Version
  • 10.0.19041.3693 (WinBuild.160101.0800)
  • 1.2508
Internal Name
  • EMS
  • wuapihost
Legal Copyright
  • OOO Sberbank-Service
  • © Microsoft Corporation. All rights reserved.
Original Filename
  • EMS.exe
  • wuapihost.exe
Product Name
  • Microsoft® Windows® Operating System
  • OpenVPN_EMS
Product Version
  • 10.0.19041.3693
  • 1.5 (r_2508)

Digital Signatures

Signer Root Status
Akeo Consulting Sectigo Public Code Signing Root R46 Hash Mismatch

File Traits

  • big overlay
  • HighEntropy
  • No Version Info
  • Py-installer
  • x64
  • zlib (In Overlay)
  • zlib overlay

Block Information

Total Blocks: 866
Potentially Malicious Blocks: 0
Whitelisted Blocks: 865
Unknown Blocks: 1

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
c:\users\user\appdata\local\temp\_mei10842\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10842\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10842\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10842\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10842\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10842\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10842\libcrypto-3.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10842\npd_suite_open.bat Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10842\python312.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10842\select.pyd Generic Write,Read Attributes
Show More
c:\users\user\appdata\local\temp\_mei10842\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10842\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11922\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11922\_ctypes.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11922\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11922\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11922\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11922\_queue.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11922\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11922\_sqlite3.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11922\_ssl.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11922\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11922\blank.aes Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11922\libcrypto-3.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11922\libffi-8.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11922\libssl-3.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11922\python311.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11922\rar.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11922\rarreg.key Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11922\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11922\sqlite3.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11922\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11922\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei13042\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei13042\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei13042\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei13042\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei13042\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei13042\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei13042\libcrypto-3.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei13042\npd_suite_open.bat Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei13042\python312.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei13042\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei13042\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei13042\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16882\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16882\_ctypes.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16882\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16882\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16882\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16882\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16882\_wmi.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16882\api-ms-win-core-console-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16882\api-ms-win-core-datetime-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16882\api-ms-win-core-debug-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16882\api-ms-win-core-errorhandling-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16882\api-ms-win-core-file-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16882\api-ms-win-core-file-l1-2-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16882\api-ms-win-core-file-l2-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16882\api-ms-win-core-handle-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16882\api-ms-win-core-heap-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16882\api-ms-win-core-interlocked-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16882\api-ms-win-core-libraryloader-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16882\api-ms-win-core-localization-l1-2-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16882\api-ms-win-core-memory-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16882\api-ms-win-core-namedpipe-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16882\api-ms-win-core-processenvironment-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16882\api-ms-win-core-processthreads-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16882\api-ms-win-core-processthreads-l1-1-1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16882\api-ms-win-core-profile-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16882\api-ms-win-core-rtlsupport-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16882\api-ms-win-core-string-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16882\api-ms-win-core-synch-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16882\api-ms-win-core-synch-l1-2-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16882\api-ms-win-core-sysinfo-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16882\api-ms-win-core-timezone-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16882\api-ms-win-core-util-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16882\api-ms-win-crt-conio-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16882\api-ms-win-crt-convert-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16882\api-ms-win-crt-environment-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16882\api-ms-win-crt-filesystem-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16882\api-ms-win-crt-heap-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16882\api-ms-win-crt-locale-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16882\api-ms-win-crt-math-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16882\api-ms-win-crt-process-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16882\api-ms-win-crt-runtime-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16882\api-ms-win-crt-stdio-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16882\api-ms-win-crt-string-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16882\api-ms-win-crt-time-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16882\api-ms-win-crt-utility-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16882\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16882\libcrypto-3.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16882\libffi-8.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16882\psutil\_psutil_windows.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16882\python3.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16882\python312.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16882\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16882\ucrtbase.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16882\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16882\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16882\vcruntime140_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18442\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18442\_ctypes.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18442\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18442\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18442\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18442\_queue.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18442\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18442\_sqlite3.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18442\_ssl.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18442\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18442\blank.aes Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18442\libcrypto-3.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18442\libffi-8.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18442\libssl-3.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18442\python311.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18442\rar.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18442\rarreg.key Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18442\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18442\sqlite3.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18442\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18442\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei19602\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei19602\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei19602\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei19602\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei19602\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei19602\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei19602\libcrypto-3.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei19602\npd_suite_open.bat Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei19602\python312.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei19602\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei19602\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei19602\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei25722\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei25722\_ctypes.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei25722\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei25722\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei25722\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei25722\_queue.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei25722\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei25722\_sqlite3.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei25722\_ssl.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei25722\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei25722\blank.aes Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei25722\libcrypto-3.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei25722\libffi-8.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei25722\libssl-3.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei25722\python311.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei25722\rar.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei25722\rarreg.key Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei25722\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei25722\sqlite3.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei25722\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei25722\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei27522\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei27522\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei27522\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei27522\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei27522\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei27522\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei27522\libcrypto-3.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei27522\npd_suite_open.bat Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei27522\python312.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei27522\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei27522\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei27522\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei2922\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei2922\_ctypes.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei2922\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei2922\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei2922\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei2922\_queue.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei2922\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei2922\_sqlite3.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei2922\_ssl.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei2922\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei2922\blank.aes Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei2922\libcrypto-3.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei2922\libffi-8.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei2922\libssl-3.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei2922\python311.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei2922\rar.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei2922\rarreg.key Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei2922\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei2922\sqlite3.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei2922\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei2922\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei29922\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei29922\_ctypes.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei29922\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei29922\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei29922\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei29922\_queue.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei29922\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei29922\_sqlite3.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei29922\_ssl.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei29922\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei29922\blank.aes Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei29922\libcrypto-3.dll Generic Write,Read Attributes

2338 additional files are not displayed above.

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAddAtomEx
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
Show More
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • UNKNOWN
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetMessage
  • win32u.dll!NtUserGetProp
  • win32u.dll!NtUserGetThreadState
  • win32u.dll!NtUserPeekMessage
  • win32u.dll!NtUserPostMessage
  • win32u.dll!NtUserShowWindow
Process Shell Execute
  • CreateProcess
Process Manipulation Evasion
  • NtUnmapViewOfSection

Shell Command Execution

c:\users\user\downloads\f95a0fa62b803094ce969b37364e3aa1d8079c52_0007776680 "c:\users\user\downloads\f95a0fa62b803094ce969b37364e3aa1d8079c52_0007776680"
c:\users\user\downloads\f95a0fa62b803094ce969b37364e3aa1d8079c52_0007776680 "c:\users\user\downloads\f95a0fa62b803094ce969b37364e3aa1d8079c52_0007776680"
c:\users\user\downloads\f95a0fa62b803094ce969b37364e3aa1d8079c52_0007776680 "c:\users\user\downloads\f95a0fa62b803094ce969b37364e3aa1d8079c52_0007776680"
c:\users\user\downloads\f95a0fa62b803094ce969b37364e3aa1d8079c52_0007776680 "c:\users\user\downloads\f95a0fa62b803094ce969b37364e3aa1d8079c52_0007776680"
c:\users\user\downloads\f95a0fa62b803094ce969b37364e3aa1d8079c52_0007776680 "c:\users\user\downloads\f95a0fa62b803094ce969b37364e3aa1d8079c52_0007776680"
Show More
c:\users\user\downloads\f95a0fa62b803094ce969b37364e3aa1d8079c52_0007776680 "c:\users\user\downloads\f95a0fa62b803094ce969b37364e3aa1d8079c52_0007776680"
c:\users\user\downloads\f95a0fa62b803094ce969b37364e3aa1d8079c52_0007776680 "c:\users\user\downloads\f95a0fa62b803094ce969b37364e3aa1d8079c52_0007776680"
c:\users\user\downloads\f95a0fa62b803094ce969b37364e3aa1d8079c52_0007776680 "c:\users\user\downloads\f95a0fa62b803094ce969b37364e3aa1d8079c52_0007776680"
c:\users\user\downloads\f95a0fa62b803094ce969b37364e3aa1d8079c52_0007776680 "c:\users\user\downloads\f95a0fa62b803094ce969b37364e3aa1d8079c52_0007776680"
c:\users\user\downloads\f95a0fa62b803094ce969b37364e3aa1d8079c52_0007776680 "c:\users\user\downloads\f95a0fa62b803094ce969b37364e3aa1d8079c52_0007776680"
c:\users\user\downloads\f95a0fa62b803094ce969b37364e3aa1d8079c52_0007776680 "c:\users\user\downloads\f95a0fa62b803094ce969b37364e3aa1d8079c52_0007776680"
c:\users\user\downloads\f95a0fa62b803094ce969b37364e3aa1d8079c52_0007776680 "c:\users\user\downloads\f95a0fa62b803094ce969b37364e3aa1d8079c52_0007776680"
c:\users\user\downloads\f95a0fa62b803094ce969b37364e3aa1d8079c52_0007776680 "c:\users\user\downloads\f95a0fa62b803094ce969b37364e3aa1d8079c52_0007776680"
c:\users\user\downloads\f95a0fa62b803094ce969b37364e3aa1d8079c52_0007776680 "c:\users\user\downloads\f95a0fa62b803094ce969b37364e3aa1d8079c52_0007776680"
c:\users\user\downloads\f95a0fa62b803094ce969b37364e3aa1d8079c52_0007776680 "c:\users\user\downloads\f95a0fa62b803094ce969b37364e3aa1d8079c52_0007776680"
c:\users\user\downloads\f95a0fa62b803094ce969b37364e3aa1d8079c52_0007776680 "c:\users\user\downloads\f95a0fa62b803094ce969b37364e3aa1d8079c52_0007776680"
c:\users\user\downloads\f95a0fa62b803094ce969b37364e3aa1d8079c52_0007776680 "c:\users\user\downloads\f95a0fa62b803094ce969b37364e3aa1d8079c52_0007776680"
c:\users\user\downloads\f95a0fa62b803094ce969b37364e3aa1d8079c52_0007776680 "c:\users\user\downloads\f95a0fa62b803094ce969b37364e3aa1d8079c52_0007776680"
c:\users\user\downloads\a16327b694085a4dec773938a38bc549d7193c6f_0007246723 "c:\users\user\downloads\a16327b694085a4dec773938a38bc549d7193c6f_0007246723"
c:\users\user\downloads\9b7e9800004beb513aeae1499d7dc6956d128458_0007658984 "c:\users\user\downloads\9b7e9800004beb513aeae1499d7dc6956d128458_0007658984"
c:\users\user\downloads\709f42ab8859fa6a55b0413fbc20e328a77d9fc2_0008297043 "c:\users\user\downloads\709f42ab8859fa6a55b0413fbc20e328a77d9fc2_0008297043"

Related Posts

Trending

Most Viewed

Loading...