PUP.HackKMS.CB

The detection of PUP.HackKMS.CB on your system indicates the presence of a potentially unwanted program (PUP) that may be causing issues with your computer's performance and security. It is essential to understand the nature of this threat and take immediate action to remove it from your system. In this report, we will provide you with an overview of PUP.HackKMS.CB, its operating methods, symptoms of infection, and a step-by-step guide on how to remove it.

What Is PUP.HackKMS.CB?

PUP.HackKMS.CB is a type of potentially unwanted program that can be installed on your system without your knowledge or consent. It may be bundled with other software or downloaded from the internet, often through deceptive means. PUPs like PUP.HackKMS.CB can cause a range of problems, including slowing down your system, displaying unwanted advertisements, and potentially leading to more severe security issues.

How PUP.HackKMS.CB Operates

PUP.HackKMS.CB operates by installing itself on your system and then executing its payload. It may use various techniques to evade detection, such as disguising itself as a legitimate program or using code obfuscation methods. Once installed, PUP.HackKMS.CB can start causing problems, including modifying system settings, displaying unwanted content, and potentially stealing sensitive information.

Symptoms of Infection

If your system is infected with PUP.HackKMS.CB, you may notice several symptoms, including slow system performance, unwanted pop-ups and advertisements, and changes to your browser settings. You may also experience issues with your system's stability, such as crashes or freezes. In some cases, PUP.HackKMS.CB may also lead to more severe security issues, such as data theft or the installation of additional malware.

  • Unwanted changes to your system settings
  • Display of unwanted advertisements and pop-ups
  • Slow system performance
  • Issues with system stability, such as crashes or freezes
  • Potential data theft or the installation of additional malware

How to Remove PUP.HackKMS.CB

  1. Boot your system in Safe Mode with Networking to prevent PUP.HackKMS.CB from loading and to allow for easier removal.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and detect any malicious components related to PUP.HackKMS.CB.
  3. Uninstall any suspicious programs that may be related to PUP.HackKMS.CB. Be cautious when uninstalling programs, as some may be legitimate or required by your system.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any unwanted changes made by PUP.HackKMS.CB.
  5. Reboot your system and perform another scan with your anti-malware tool to ensure that all components of PUP.HackKMS.CB have been removed.

Conclusion

Removing PUP.HackKMS.CB from your system requires careful attention to detail and a thorough understanding of the steps involved. By following the guidance outlined in this report, you can effectively remove PUP.HackKMS.CB and restore your system to a safe and secure state. It is essential to remain vigilant and take proactive measures to protect your system from future threats, including keeping your operating system and software up to date, using reputable anti-malware tools, and being cautious when downloading software or clicking on links from unknown sources.

Analysis Report

General information

Family Name: PUP.HackKMS.CB
Signature status: No Signature

Known Samples

MD5: e2c6062442c921589db6760fb8f8eefe
SHA1: 378f5b596c5731ecfca74326b23a18b9653b6efb
SHA256: F8C2EC9CA93DDBD3069CE5C974D54F57286814A6BCB80350926BB253EF4AE075
File Size: 3.03 MB, 3031040 bytes
MD5: f742621303931fd5143fc1de56acdb50
SHA1: 8ae77df00cc9cce52d034b187a2d308ce3c37b7b
SHA256: A1EA5C138C1BEF795D5F4CE46C91956AD81D1B994D04BAE7F5ACA3A69132BFB5
File Size: 1.84 MB, 1842688 bytes
MD5: bef176669df519c0677900f17ccb0ab8
SHA1: a1423d1e0e5418dc9eb5bda85cc7d8a37826c822
SHA256: BE231F5DCCDD232A0E8942C620739E6C9135F64A6E5771039E1E6BAC1A313C02
File Size: 6.43 MB, 6426112 bytes
MD5: 30e73d69f1a312e7bbaa367debc6ac7c
SHA1: db07bece6d4762a3feb6c3d16d9c61266b2d846e
SHA256: C6B809A272DA823980ADB68A7E2BC2D360B958425756C9CA22AC793F2B319F14
File Size: 2.37 MB, 2368512 bytes
MD5: 63b8156bd520a2472ff6c2e4f481cab7
SHA1: 26392265c5c4d01930adc1d1b2bbe700ca4ecad5
SHA256: 5A7F25256F373E04C71DF1830CEE7109D85DC596E78955A25DFDF8E9AB5DE790
File Size: 6.27 MB, 6273536 bytes
Show More
MD5: f2114527cf9fd077eca65daa1480e00e
SHA1: 66f3c05ff5bd5d1e0df913ec9b58aa70d1431861
SHA256: 9BE585AEEB975FD474A8E80D89E19F6939D73AD0A213D85E6FAEA97FF27A0F08
File Size: 7.08 MB, 7081984 bytes
MD5: e1a84cf4d6eaaa76b0a1c65f25322e29
SHA1: 373a93f7defc2dd511a788958f78ac26bd7c739e
SHA256: 65A1460F449FC453358F6F1FCEFC5724354BB65B5629759FBEA7E2609FC1441B
File Size: 2.37 MB, 2369536 bytes
MD5: add4acb6feecef1de7dc498156b98553
SHA1: e57131cff902e877abe436c9c924446e76704528
SHA256: CF5BEDDE025722483EF8A5223491365FC07223F373E60C6CD1221978EEF685CB
File Size: 2.95 MB, 2948608 bytes
MD5: f3218226af20edd7ee701db29b03db30
SHA1: 3284e4d160a0491e852e689964a24e29038d10cd
SHA256: 599A53520ECE303221649DE6305F9ADBC414D5CB0420B777009D62BEEABB2181
File Size: 2.83 MB, 2831872 bytes
MD5: 5a3694fdbb4671e0115abc617d940e71
SHA1: 8c2d3b4992366bc67d329946e7f7cdd1206752c1
SHA256: 6036475CED9894645C5E972B26F54BADD39C5C531DF157E0A843DC9FC9ACFA7F
File Size: 7.12 MB, 7116288 bytes
MD5: e7bf7b88e827aa157b8b3168b1eb7858
SHA1: a206873a8d6f9d75c95f8dea08342a7f16ea9b50
SHA256: 1F28CACAB7B87E0335AFFC6F1B5C990875109A694E6CA03D40E7B4AB6E9B640D
File Size: 1.78 MB, 1784320 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has TLS information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comment
  • Build Date: 02/12/2025 - 15:56:09 (free version)
  • Build Date: 06/09/2025 - 16:04:08
  • Build Date: 06/09/2025 - 16:12:21 (free version)
Company Name
  • Fantaisie Software
  • Language Pack Italia
Email languagepack.italia@gmail.com
File Description PureBasic Development Environment
Internal Name PureBasicIDE
Legal Copyright (c) 2025 Fantaisie Software
Original Filename PureBasic.exe
Product Name
  • LPIHub
  • PureBasic
Product Version
  • PureBasic 6.21 (Windows - x64)
  • PureBasic 6.20 (Windows - x64)
Special Build Free Version: Register your version at http://www.purebasic.com
Website https://languagepack.it/

File Traits

  • 2+ executable sections
  • HighEntropy
  • imgui
  • No Version Info
  • x64

Block Information

Total Blocks: 5,158
Potentially Malicious Blocks: 54
Whitelisted Blocks: 4,052
Unknown Blocks: 1,052

Visual Map

0 0 0 ? ? ? ? 0 ? ? 0 x ? ? 0 x x x 0 ? 0 ? 0 ? ? ? ? ? ? ? ? 0 ? 0 ? ? ? ? 0 0 0 0 ? ? 0 ? ? ? ? 0 ? 0 ? ? 0 0 0 ? 0 0 ? ? 0 ? ? ? ? 0 0 ? ? 0 ? ? 0 0 ? ? 0 ? 0 0 0 0 0 0 0 0 0 ? ? ? ? 0 0 ? 0 ? 0 0 ? 0 ? ? 0 ? 0 ? ? ? ? ? ? ? ? ? 0 ? ? 0 0 0 0 ? 0 0 0 ? ? ? ? ? 0 x ? 0 0 ? 0 0 ? 0 0 ? ? 0 0 0 ? 0 0 ? ? ? ? ? ? ? 0 ? 0 ? 0 ? ? ? 0 ? 0 ? ? ? ? ? ? ? ? 0 ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? 0 ? ? ? 0 ? ? 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? 0 0 0 ? ? 0 ? 0 0 ? ? ? 0 ? ? 0 ? ? ? 0 ? ? 0 ? ? ? ? 0 ? 0 0 0 ? ? 0 ? 0 ? 0 ? ? ? ? ? ? 0 ? ? ? ? 0 0 0 ? 0 ? 0 ? ? ? ? ? 0 0 0 ? 0 0 0 ? 0 ? 0 0 ? x ? ? ? 0 ? ? ? 0 ? ? ? 0 ? ? ? ? 0 ? 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 ? ? ? ? ? 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 ? ? ? ? ? ? ? ? 0 0 ? ? ? 0 ? ? 0 ? ? 0 ? ? ? 0 ? ? ? 0 ? ? 0 ? ? ? ? 0 0 ? ? ? 0 ? ? 0 0 ? 0 ? ? ? ? ? ? 0 0 ? ? ? 0 ? 0 ? ? ? ? x ? ? 0 ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? 0 ? 0 0 ? ? ? 0 0 ? ? 0 ? ? ? ? ? ? 0 0 ? ? 0 ? 0 0 0 ? ? 0 0 0 ? 0 ? 0 0 ? 0 0 ? ? ? ? ? ? ? ? ? 0 0 0 0 0 ? ? ? 0 0 ? 0 ? 0 0 ? ? ? 0 ? 0 0 ? 0 0 0 x ? ? 0 0 0 0 ? ? 0 ? x ? ? 0 ? 0 ? ? ? ? ? ? ? ? x x ? ? x ? ? 0 ? 0 0 ? ? x 0 ? ? ? 0 0 ? ? ? 0 0 ? 0 ? x ? ? ? 0 ? 0 0 0 ? 0 ? ? ? 0 0 0 ? 0 ? 0 ? ? 0 ? ? ? ? ? 0 ? ? 0 ? ? ? ? 0 ? ? 0 ? ? ? ? ? ? ? ? ? ? 0 ? ? 0 ? ? 0 ? ? ? ? ? ? 0 ? ? 0 ? ? ? 0 0 ? ? ? 0 ? ? ? ? ? ? ? 0 ? 0 0 0 0 0 0 ? ? ? 0 ? ? 0 ? ? 0 0 0 ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? 0 ? ? ? ? ? 0 0 ? 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? 0 0 ? ? 0 0 0 0 ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? ? ? 0 0 ? ? ? ? 0 ? ? ? ? 0 ? ? ? ? 0 ? ? ? ? ? ? 0 ? 0 ? ? 0 ? ? ? ? ? ? ? 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? ? ? 0 0 ? ? 0 ? 0 ? ? ? ? 0 ? ? 0 0 ? ? ? 0 ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 ? 0 ? 0 ? 0 ? ? ? ? ? 0 ? ? 0 ? ? ? ? 0 0 ? 0 ? ? 0 ? ? ? ? ? ? ? 0 ? 0 0 ? ? ? 0 ? 0 0 ? 0 ? ? ? 0 ? ? 0 ? ? 0 ? ? 0 ? ? ? 0 ? ? ? 0 ? ? ? ? 0 ? ? 0 0 ? ? ? 0 0 ? 0 ? ? 0 ? ? ? ? ? 0 ? 0 ? ? 0 0 0 ? ? ? 0 ? 0 ? 0 ? ? ? ? 0 ? ? ? ? ? ? 0 ? ? ? ? ? ? ? 0 x ? ? ? ? x ? 0 0 ? ? ? ? 0 ? ? ? 0 0 ? ? ? ? 0 ? ? ? ? ? 0 ? ? ? 0 x ? ? ? ? 0 ? 0 ? 0 0 ? ? ? ? ? 0 0 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? ? ? ? 0 ? 0 ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? 0 0 ? ? 0 ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? 0 ? 0 ? 0 0 0 0 ? 0 ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? 0 ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? ? ? ? ? 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 x 0 x 0 ? 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 0 0 0 0 x 0 x 0 x 0 0 0 0 x x 0 0 0 0 0 ? ? 0 0 0 0 0 ? ? ? ? ? 0 ? ? 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 ? 0 0 ? 0 ? ? ? 0 ? ? ? 0 0 ? ? 0 0 ? ? 0 ? ? ? ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? 0 0 0 0 ? 0 0 0 0 ? 0 0 0 ? 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 ? x 0 0 0 0 0 0 0 0 0 0 0 0 x ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • HackKMS.C
  • HackKMS.CB
  • HackKMS.JA

Files Modified

File Attributes
\device\namedpipe Generic Read,Write Attributes
\device\namedpipe Generic Write,Read Attributes
c:\users\user\appdata\roaming\purebasic\purebasic.prefs Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\purebasic\tools.prefs Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\downloads\$autoinicio Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\downloads\lastversion.txt Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\downloads\paises\countrylist.txt Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\downloads\paises\countrylist.txt Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKCU\26392265c5c4d01930adc1d1b2bbe700ca4ecad5_0006273536\shell\open\command:: "c:\users\user\downloads\26392265c5c4d01930adc1d1b2bbe700ca4ecad5_0006273536" "%1" /P "C:\Users\Ahzgmrdl\AppData\Roaming\PureBas RegNtPreCreateKey
HKCU\26392265c5c4d01930adc1d1b2bbe700ca4ecad5_0006273536\defaulticon:: c:\users\user\downloads\26392265c5c4d01930adc1d1b2bbe700ca4ecad5_0006273536,1 RegNtPreCreateKey
HKCU\.pb:: 26392265c5c4d01930adc1d1b2bbe700ca4ecad5_0006273536 RegNtPreCreateKey
HKCU\.pbi:: 26392265c5c4d01930adc1d1b2bbe700ca4ecad5_0006273536 RegNtPreCreateKey
HKCU\.pbp:: 26392265c5c4d01930adc1d1b2bbe700ca4ecad5_0006273536 RegNtPreCreateKey
HKCU\.pbf:: 26392265c5c4d01930adc1d1b2bbe700ca4ecad5_0006273536 RegNtPreCreateKey
HKCU\66f3c05ff5bd5d1e0df913ec9b58aa70d1431861_0007081984\shell\open\command:: "c:\users\user\downloads\66f3c05ff5bd5d1e0df913ec9b58aa70d1431861_0007081984" "%1" /P "C:\Users\Judkbjjd\AppData\Roaming\PureBas RegNtPreCreateKey
HKCU\66f3c05ff5bd5d1e0df913ec9b58aa70d1431861_0007081984\defaulticon:: c:\users\user\downloads\66f3c05ff5bd5d1e0df913ec9b58aa70d1431861_0007081984,1 RegNtPreCreateKey
HKCU\.pb:: 66f3c05ff5bd5d1e0df913ec9b58aa70d1431861_0007081984 RegNtPreCreateKey
HKCU\.pbi:: 66f3c05ff5bd5d1e0df913ec9b58aa70d1431861_0007081984 RegNtPreCreateKey
Show More
HKCU\.pbp:: 66f3c05ff5bd5d1e0df913ec9b58aa70d1431861_0007081984 RegNtPreCreateKey
HKCU\.pbf:: 66f3c05ff5bd5d1e0df913ec9b58aa70d1431861_0007081984 RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 馆롔ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 钼뢽ǜ RegNtPreCreateKey
HKCU\8c2d3b4992366bc67d329946e7f7cdd1206752c1_0007116288\shell\open\command:: "c:\users\user\downloads\8c2d3b4992366bc67d329946e7f7cdd1206752c1_0007116288" "%1" /P "C:\Users\Jetsyvzp\AppData\Roaming\PureBas RegNtPreCreateKey
HKCU\8c2d3b4992366bc67d329946e7f7cdd1206752c1_0007116288\defaulticon:: c:\users\user\downloads\8c2d3b4992366bc67d329946e7f7cdd1206752c1_0007116288,1 RegNtPreCreateKey
HKCU\.pb:: 8c2d3b4992366bc67d329946e7f7cdd1206752c1_0007116288 RegNtPreCreateKey
HKCU\.pbi:: 8c2d3b4992366bc67d329946e7f7cdd1206752c1_0007116288 RegNtPreCreateKey
HKCU\.pbp:: 8c2d3b4992366bc67d329946e7f7cdd1206752c1_0007116288 RegNtPreCreateKey
HKCU\.pbf:: 8c2d3b4992366bc67d329946e7f7cdd1206752c1_0007116288 RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe ꊭǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 勺ꍔǜ RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAccessCheckByType
  • ntdll.dll!NtAddAtomEx
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcAcceptConnectPort
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcCreatePort
  • ntdll.dll!NtAlpcCreateSecurityContext
  • ntdll.dll!NtAlpcDeleteSecurityContext
Show More
  • ntdll.dll!NtAlpcOpenSenderProcess
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtAlpcSetInformation
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtCompareSigningLevels
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtDelayExecution
  • ntdll.dll!NtDeleteValueKey
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFindAtom
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtGetCachedSigningLevel
  • ntdll.dll!NtImpersonateAnonymousToken
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenMutant
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenSymbolicLinkObject
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtPowerInformation
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDirectoryFile
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryObject
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySymbolicLinkObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryTimerResolution
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReadVirtualMemory
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationObject
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSetTimerEx
  • ntdll.dll!NtSetTimerResolution
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTerminateProcess
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl

67 additional items are not displayed above.

User Data Access
  • GetUserDefaultLocaleName
  • GetUserName
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
Network Winsock2
  • WSAStartup
Process Shell Execute
  • CreateProcess
  • WriteConsole
Keyboard Access
  • GetKeyState
Process Manipulation Evasion
  • NtUnmapViewOfSection
Other Suspicious
  • AdjustTokenPrivileges
Process Terminate
  • TerminateProcess

Shell Command Execution

"c:\users\user\downloads\Compilers\pbcompilerc.exe" /VERSION
"c:\users\user\downloads\Compilers\pbcompiler.exe" /STANDBY
"taskkill.exe" /f /IM gmscentinela.dat
WriteConsole: ERROR: The proce
"taskkill.exe" /f /IM gmscentinela.exe

Related Posts

Trending

Most Viewed

Loading...