PUP.Bulz.EA

Analysis Report

General information

Family Name: PUP.Bulz.EA
Signature status: No Signature

Known Samples

MD5: 48a17958a04905f7b6906f644f23dd20
SHA1: dabbfee68acc6201bcf3a556293bee45559a94e3
SHA256: 44DEE38D6064A0F216EAE375F7237370F545A19F8D2DC9D28A64317940212A16
File Size: 5.01 MB, 5007645 bytes
MD5: 122e177d77ef5064c12431c82a7e0f9a
SHA1: 0761469718c5e4ba8f7c137fbced9a557ee37e74
SHA256: 04AED3CFB3824F161542647ED0B50FAFDE31BF23B4BC63EDCABDA259731E7E1C
File Size: 1.22 MB, 1217543 bytes
MD5: 3cba83a2a095227064c69283e3b1a7ec
SHA1: b8cbbb106e4f9f75baaa7ee304a28d4fa974cb84
SHA256: AF89046702800692A5694332C93A0D2D00CC03997EDD6523EFF111E8092417F5
File Size: 5.69 MB, 5688476 bytes
MD5: 7de9ef1409dfd34405c4fab5a056b3e0
SHA1: aa65355656c6f721803dc1be9e7c5fc6462a26e1
SHA256: 7FDAA2CF377042CAB81C02E3B1280EB2F26ED719EE9D900316EB6231AB4C2825
File Size: 7.31 MB, 7306092 bytes
MD5: bc172a6b9bfbf8ae6fdc81c3c465a338
SHA1: fabeaff0a9e77299c4bac1024d0a84a698d2ab09
SHA256: A030AF27E56386BBDF6B01E9D6B1AD7D371EC8689291A0A97222FEB13B5B81AB
File Size: 8.85 MB, 8853555 bytes
Show More
MD5: 2a51d449f9a6ea141876992c36f9f6f6
SHA1: 0dade6f37cfa2308bb663a43ab3fe4470a6d8687
SHA256: F8406FFF01529D39127336AB9132C74F427D554C7293B356CB6F363B86DC2BC3
File Size: 6.26 MB, 6256302 bytes
MD5: 41412d16cdc6f653e2781b58e06dba8e
SHA1: e3a6c10a8c56f1b7fa1d3da79f206211235f20db
SHA256: C6FA8803C361E3668A6D9725BF7989D357DBA306F81B8AEBC10A7F5284351A54
File Size: 4.57 MB, 4568362 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

File Traits

  • GetConsoleWindow
  • No Version Info
  • Py-installer
  • x64
  • zlib (In Overlay)
  • zlib overlay

Block Information

Total Blocks: 862
Potentially Malicious Blocks: 2
Whitelisted Blocks: 860
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 2 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • CobaltStrike.XAA
  • Downloader.Agent.N

Files Modified

File Attributes
c:\users\user\appdata\local\temp\_mei10522\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10522\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10522\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10522\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10522\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10522\_wmi.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10522\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10522\libcrypto-3.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10522\python312.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10522\select.pyd Generic Write,Read Attributes
Show More
c:\users\user\appdata\local\temp\_mei10522\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10522\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei12082\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei12082\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei12082\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei12082\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei12082\_queue.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei12082\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei12082\_ssl.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei12082\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei12082\certifi\cacert.pem Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei12082\certifi\py.typed Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei12082\charset_normalizer\md.cp311-win_amd64.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei12082\charset_normalizer\md__mypyc.cp311-win_amd64.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei12082\libcrypto-3.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei12082\libssl-3.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei12082\python3.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei12082\python311.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei12082\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei12082\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei12082\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei12082\zstandard\_cffi.cp311-win_amd64.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei12082\zstandard\backend_c.cp311-win_amd64.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\api-ms-win-core-console-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\api-ms-win-core-datetime-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\api-ms-win-core-debug-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\api-ms-win-core-errorhandling-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\api-ms-win-core-file-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\api-ms-win-core-file-l1-2-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\api-ms-win-core-file-l2-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\api-ms-win-core-handle-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\api-ms-win-core-heap-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\api-ms-win-core-interlocked-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\api-ms-win-core-libraryloader-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\api-ms-win-core-localization-l1-2-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\api-ms-win-core-memory-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\api-ms-win-core-namedpipe-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\api-ms-win-core-processenvironment-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\api-ms-win-core-processthreads-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\api-ms-win-core-processthreads-l1-1-1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\api-ms-win-core-profile-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\api-ms-win-core-rtlsupport-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\api-ms-win-core-string-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\api-ms-win-core-synch-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\api-ms-win-core-synch-l1-2-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\api-ms-win-core-sysinfo-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\api-ms-win-core-timezone-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\api-ms-win-core-util-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\api-ms-win-crt-conio-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\api-ms-win-crt-convert-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\api-ms-win-crt-environment-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\api-ms-win-crt-filesystem-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\api-ms-win-crt-heap-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\api-ms-win-crt-locale-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\api-ms-win-crt-math-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\api-ms-win-crt-process-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\api-ms-win-crt-runtime-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\api-ms-win-crt-stdio-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\api-ms-win-crt-string-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\api-ms-win-crt-time-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\api-ms-win-crt-utility-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\libcrypto-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\python310.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\ucrtbase.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17242\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17242\_ctypes.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17242\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17242\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17242\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17242\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17242\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17242\libcrypto-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17242\libffi-7.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17242\psutil\_psutil_windows.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17242\python3.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17242\python39.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17242\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17242\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17242\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17322\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17322\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17322\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei22122\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei22122\_ctypes.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei22122\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei22122\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei22122\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei22122\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei22122\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei22122\libcrypto-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei22122\libffi-7.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei22122\psutil\_psutil_windows.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei22122\python3.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei22122\python39.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei22122\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei22122\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei22122\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei34602\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei34602\_ctypes.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei34602\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei34602\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei34602\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei34602\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei34602\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei34602\libcrypto-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei34602\libffi-7.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei34602\psutil\_psutil_windows.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei34602\python3.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei34602\python39.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei34602\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei34602\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei34602\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei34682\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei34682\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei34682\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei34682\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei34682\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei34682\_wmi.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei34682\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei34682\libcrypto-3.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei34682\python312.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei34682\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei34682\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei34682\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35162\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35162\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35162\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35162\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35162\_queue.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35162\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35162\_ssl.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35162\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35162\certifi\cacert.pem Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35162\certifi\py.typed Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35162\charset_normalizer\md.cp311-win_amd64.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35162\charset_normalizer\md__mypyc.cp311-win_amd64.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35162\libcrypto-3.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35162\libssl-3.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35162\python3.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35162\python311.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35162\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35162\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35162\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35162\zstandard\_cffi.cp311-win_amd64.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35162\zstandard\backend_c.cp311-win_amd64.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35362\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35362\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35362\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35362\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35362\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35362\api-ms-win-core-console-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35362\api-ms-win-core-datetime-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35362\api-ms-win-core-debug-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35362\api-ms-win-core-errorhandling-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35362\api-ms-win-core-file-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35362\api-ms-win-core-file-l1-2-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35362\api-ms-win-core-file-l2-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35362\api-ms-win-core-handle-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35362\api-ms-win-core-heap-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35362\api-ms-win-core-interlocked-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35362\api-ms-win-core-libraryloader-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35362\api-ms-win-core-localization-l1-2-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35362\api-ms-win-core-memory-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35362\api-ms-win-core-namedpipe-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35362\api-ms-win-core-processenvironment-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35362\api-ms-win-core-processthreads-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35362\api-ms-win-core-processthreads-l1-1-1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35362\api-ms-win-core-profile-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35362\api-ms-win-core-rtlsupport-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35362\api-ms-win-core-string-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35362\api-ms-win-core-synch-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35362\api-ms-win-core-synch-l1-2-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35362\api-ms-win-core-sysinfo-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35362\api-ms-win-core-timezone-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35362\api-ms-win-core-util-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35362\api-ms-win-crt-conio-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35362\api-ms-win-crt-convert-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35362\api-ms-win-crt-environment-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35362\api-ms-win-crt-filesystem-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35362\api-ms-win-crt-heap-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35362\api-ms-win-crt-locale-l1-1-0.dll Generic Write,Read Attributes

895 additional files are not displayed above.

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
Show More
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWriteFile
  • UNKNOWN
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess

Shell Command Execution

c:\users\user\downloads\b8cbbb106e4f9f75baaa7ee304a28d4fa974cb84_0005688476 "c:\users\user\downloads\b8cbbb106e4f9f75baaa7ee304a28d4fa974cb84_0005688476"
c:\users\user\downloads\aa65355656c6f721803dc1be9e7c5fc6462a26e1_0007306092 "c:\users\user\downloads\aa65355656c6f721803dc1be9e7c5fc6462a26e1_0007306092"
c:\users\user\downloads\fabeaff0a9e77299c4bac1024d0a84a698d2ab09_0008853555 "c:\users\user\downloads\fabeaff0a9e77299c4bac1024d0a84a698d2ab09_0008853555"
c:\users\user\downloads\0dade6f37cfa2308bb663a43ab3fe4470a6d8687_0006256302 "c:\users\user\downloads\0dade6f37cfa2308bb663a43ab3fe4470a6d8687_0006256302"

Trending

Most Viewed

Loading...