PUP.BadJoke.PG

Analysis Report

General information

Family Name: PUP.BadJoke.PG
Signature status: No Signature

Known Samples

MD5: 3f88af2ff6c929380294ea6b406de9aa
SHA1: f95a0fa62b803094ce969b37364e3aa1d8079c52
SHA256: 7A8BA863B86526B5AA7EB5EFEA18415162AEF77A8CB1F2C328BF42EDD3853B39
File Size: 7.78 MB, 7776680 bytes
MD5: f3319e077821a570a0192f3dad703296
SHA1: a16327b694085a4dec773938a38bc549d7193c6f
SHA256: F36AE1E772B4A7E4A54803ABC23EA5800DC68804079A41799C1EF3E71B09230D
File Size: 7.25 MB, 7246723 bytes
MD5: 7671e25ff8f1b8e884fd35bdc2b5ffcf
SHA1: 481c6db2efb156aa46d99b02be519a362a43a6bc
SHA256: 3B0B01232BDE3E033B4E2FC05261E5BB1A73CEE7238075CDEF6A83649F1DB583
File Size: 9.21 MB, 9214013 bytes
MD5: 2d480b6a0e67fc2eabd57f7cc1ff5e1f
SHA1: 9b7e9800004beb513aeae1499d7dc6956d128458
SHA256: 2CFE31839810AAE617E8E1CDDA045670FDDDAEB59CD50C3FC4AECBAF175F046A
File Size: 7.66 MB, 7658984 bytes
MD5: 5c6f46b52b07f2255022bdf6e524190e
SHA1: 78b3deabff41b20af47c23c6ed91739e111405ea
SHA256: 92121DBBD29B667A520DBE2058303E07FF383976CCB8AB360656F3A5AA6E8DB0
File Size: 5.65 MB, 5649700 bytes
Show More
MD5: d22d4c1e29a7a80a8c902fa0c94bbebb
SHA1: 394625c48cf2cb000cdaeb26a3171ebab30f2d58
SHA256: D535C15D6910F99F2C2F1C837567C14A57DD601FDCED6716C97F0910BD50D195
File Size: 6.70 MB, 6698774 bytes
MD5: 3924ad878bd22fdfe5623df44cd9ec65
SHA1: ba857ebd5dc755f6a694400e49fa839573f5b202
SHA256: 67621B75460DA03AC84F932B34818424A3A2368C73AB24F37824FF8A8E05B454
File Size: 2.06 MB, 2063692 bytes
MD5: 4319345dedfe50b7efea004e0123f831
SHA1: 97c0366a31b1cdc0548170d33024c6483fc748e3
SHA256: 50A739948F01ABD7B5901FBFA568426ABA97F9DE082FB83F4C786E9079E5F392
File Size: 1.95 MB, 1948288 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name
  • Microsoft Corporation
  • OOO Sberbank-Service
File Description
  • EMS
  • wuapihost
File Version
  • 10.0.19041.3693 (WinBuild.160101.0800)
  • 1.2508
Internal Name
  • EMS
  • wuapihost
Legal Copyright
  • OOO Sberbank-Service
  • © Microsoft Corporation. All rights reserved.
Original Filename
  • EMS.exe
  • wuapihost.exe
Product Name
  • Microsoft® Windows® Operating System
  • OpenVPN_EMS
Product Version
  • 10.0.19041.3693
  • 1.5 (r_2508)

Digital Signatures

Signer Root Status
Akeo Consulting Sectigo Public Code Signing Root R46 Hash Mismatch

File Traits

  • big overlay
  • HighEntropy
  • No Version Info
  • Py-installer
  • x64
  • zlib (In Overlay)
  • zlib overlay

Block Information

Total Blocks: 866
Potentially Malicious Blocks: 5
Whitelisted Blocks: 861
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x x 0 0 0 0 0 x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
c:\users\user\appdata\local\temp\_mei10842\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10842\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10842\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10842\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10842\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10842\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10842\libcrypto-3.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10842\npd_suite_open.bat Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10842\python312.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10842\select.pyd Generic Write,Read Attributes
Show More
c:\users\user\appdata\local\temp\_mei10842\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10842\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11922\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11922\_ctypes.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11922\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11922\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11922\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11922\_queue.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11922\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11922\_sqlite3.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11922\_ssl.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11922\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11922\blank.aes Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11922\libcrypto-3.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11922\libffi-8.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11922\libssl-3.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11922\python311.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11922\rar.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11922\rarreg.key Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11922\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11922\sqlite3.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11922\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11922\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei13042\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei13042\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei13042\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei13042\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei13042\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei13042\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei13042\libcrypto-3.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei13042\npd_suite_open.bat Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei13042\python312.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei13042\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei13042\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei13042\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18442\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18442\_ctypes.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18442\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18442\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18442\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18442\_queue.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18442\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18442\_sqlite3.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18442\_ssl.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18442\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18442\blank.aes Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18442\libcrypto-3.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18442\libffi-8.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18442\libssl-3.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18442\python311.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18442\rar.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18442\rarreg.key Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18442\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18442\sqlite3.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18442\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18442\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei19602\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei19602\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei19602\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei19602\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei19602\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei19602\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei19602\libcrypto-3.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei19602\npd_suite_open.bat Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei19602\python312.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei19602\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei19602\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei19602\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei25722\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei25722\_ctypes.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei25722\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei25722\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei25722\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei25722\_queue.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei25722\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei25722\_sqlite3.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei25722\_ssl.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei25722\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei25722\blank.aes Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei25722\libcrypto-3.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei25722\libffi-8.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei25722\libssl-3.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei25722\python311.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei25722\rar.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei25722\rarreg.key Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei25722\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei25722\sqlite3.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei25722\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei25722\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei27522\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei27522\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei27522\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei27522\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei27522\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei27522\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei27522\libcrypto-3.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei27522\npd_suite_open.bat Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei27522\python312.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei27522\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei27522\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei27522\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei2922\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei2922\_ctypes.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei2922\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei2922\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei2922\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei2922\_queue.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei2922\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei2922\_sqlite3.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei2922\_ssl.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei2922\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei2922\blank.aes Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei2922\libcrypto-3.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei2922\libffi-8.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei2922\libssl-3.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei2922\python311.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei2922\rar.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei2922\rarreg.key Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei2922\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei2922\sqlite3.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei2922\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei2922\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei29922\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei29922\_ctypes.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei29922\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei29922\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei29922\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei29922\_queue.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei29922\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei29922\_sqlite3.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei29922\_ssl.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei29922\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei29922\blank.aes Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei29922\libcrypto-3.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei29922\libffi-8.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei29922\libssl-3.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei29922\python311.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei29922\rar.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei29922\rarreg.key Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei29922\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei29922\sqlite3.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei29922\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei29922\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30442\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30442\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30442\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30442\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30442\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30442\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30442\libcrypto-3.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30442\npd_suite_open.bat Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30442\python312.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30442\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30442\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30442\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei32362\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei32362\_ctypes.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei32362\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei32362\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei32362\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei32362\_queue.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei32362\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei32362\_sqlite3.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei32362\_ssl.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei32362\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei32362\blank.aes Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei32362\libcrypto-3.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei32362\libffi-8.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei32362\libssl-3.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei32362\python311.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei32362\rar.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei32362\rarreg.key Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei32362\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei32362\sqlite3.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei32362\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei32362\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35242\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35242\_ctypes.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35242\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35242\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35242\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35242\_queue.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35242\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35242\_sqlite3.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35242\_ssl.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35242\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35242\blank.aes Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35242\libcrypto-3.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35242\libffi-8.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35242\libssl-3.dll Generic Write,Read Attributes

1946 additional files are not displayed above.

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAddAtomEx
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
Show More
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • UNKNOWN
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetMessage
  • win32u.dll!NtUserGetProp
  • win32u.dll!NtUserGetThreadState
  • win32u.dll!NtUserPeekMessage
  • win32u.dll!NtUserPostMessage
  • win32u.dll!NtUserShowWindow
Process Shell Execute
  • CreateProcess
Process Manipulation Evasion
  • NtUnmapViewOfSection

Shell Command Execution

c:\users\user\downloads\f95a0fa62b803094ce969b37364e3aa1d8079c52_0007776680 "c:\users\user\downloads\f95a0fa62b803094ce969b37364e3aa1d8079c52_0007776680"
c:\users\user\downloads\f95a0fa62b803094ce969b37364e3aa1d8079c52_0007776680 "c:\users\user\downloads\f95a0fa62b803094ce969b37364e3aa1d8079c52_0007776680"
c:\users\user\downloads\f95a0fa62b803094ce969b37364e3aa1d8079c52_0007776680 "c:\users\user\downloads\f95a0fa62b803094ce969b37364e3aa1d8079c52_0007776680"
c:\users\user\downloads\f95a0fa62b803094ce969b37364e3aa1d8079c52_0007776680 "c:\users\user\downloads\f95a0fa62b803094ce969b37364e3aa1d8079c52_0007776680"
c:\users\user\downloads\f95a0fa62b803094ce969b37364e3aa1d8079c52_0007776680 "c:\users\user\downloads\f95a0fa62b803094ce969b37364e3aa1d8079c52_0007776680"
Show More
c:\users\user\downloads\f95a0fa62b803094ce969b37364e3aa1d8079c52_0007776680 "c:\users\user\downloads\f95a0fa62b803094ce969b37364e3aa1d8079c52_0007776680"
c:\users\user\downloads\f95a0fa62b803094ce969b37364e3aa1d8079c52_0007776680 "c:\users\user\downloads\f95a0fa62b803094ce969b37364e3aa1d8079c52_0007776680"
c:\users\user\downloads\f95a0fa62b803094ce969b37364e3aa1d8079c52_0007776680 "c:\users\user\downloads\f95a0fa62b803094ce969b37364e3aa1d8079c52_0007776680"
c:\users\user\downloads\f95a0fa62b803094ce969b37364e3aa1d8079c52_0007776680 "c:\users\user\downloads\f95a0fa62b803094ce969b37364e3aa1d8079c52_0007776680"
c:\users\user\downloads\f95a0fa62b803094ce969b37364e3aa1d8079c52_0007776680 "c:\users\user\downloads\f95a0fa62b803094ce969b37364e3aa1d8079c52_0007776680"
c:\users\user\downloads\f95a0fa62b803094ce969b37364e3aa1d8079c52_0007776680 "c:\users\user\downloads\f95a0fa62b803094ce969b37364e3aa1d8079c52_0007776680"
c:\users\user\downloads\f95a0fa62b803094ce969b37364e3aa1d8079c52_0007776680 "c:\users\user\downloads\f95a0fa62b803094ce969b37364e3aa1d8079c52_0007776680"
c:\users\user\downloads\f95a0fa62b803094ce969b37364e3aa1d8079c52_0007776680 "c:\users\user\downloads\f95a0fa62b803094ce969b37364e3aa1d8079c52_0007776680"
c:\users\user\downloads\f95a0fa62b803094ce969b37364e3aa1d8079c52_0007776680 "c:\users\user\downloads\f95a0fa62b803094ce969b37364e3aa1d8079c52_0007776680"
c:\users\user\downloads\f95a0fa62b803094ce969b37364e3aa1d8079c52_0007776680 "c:\users\user\downloads\f95a0fa62b803094ce969b37364e3aa1d8079c52_0007776680"
c:\users\user\downloads\f95a0fa62b803094ce969b37364e3aa1d8079c52_0007776680 "c:\users\user\downloads\f95a0fa62b803094ce969b37364e3aa1d8079c52_0007776680"
c:\users\user\downloads\f95a0fa62b803094ce969b37364e3aa1d8079c52_0007776680 "c:\users\user\downloads\f95a0fa62b803094ce969b37364e3aa1d8079c52_0007776680"
c:\users\user\downloads\f95a0fa62b803094ce969b37364e3aa1d8079c52_0007776680 "c:\users\user\downloads\f95a0fa62b803094ce969b37364e3aa1d8079c52_0007776680"
c:\users\user\downloads\a16327b694085a4dec773938a38bc549d7193c6f_0007246723 "c:\users\user\downloads\a16327b694085a4dec773938a38bc549d7193c6f_0007246723"
c:\users\user\downloads\9b7e9800004beb513aeae1499d7dc6956d128458_0007658984 "c:\users\user\downloads\9b7e9800004beb513aeae1499d7dc6956d128458_0007658984"

Trending

Most Viewed

Loading...