PUP.Nuitika.A

Analysis Report

General information

Family Name: PUP.Nuitika.A
Signature status: No Signature

Known Samples

MD5: 89b89fcb4d0309478e64c5571bbbc932
SHA1: 55eabcd94a2b2da1b6c4eccdd6691f57f74feacc
SHA256: 05D6517EBF1770D75EBEFE0DA842DD8062912C05A2732EB53A71A54A37672DC0
File Size: 8.32 MB, 8319488 bytes
MD5: 1e6300233cffc0ca4fc5e6b0214d33d8
SHA1: 27e5ed8f1a4c741c0c3b960d679f8e802b798d48
SHA256: 047B1357119FF4BC5D54F03901234BCC031FA09F88A64593500AD81888784C84
File Size: 7.62 MB, 7619584 bytes
MD5: e41435b328b4aaf78ce6f82af4e0efbd
SHA1: f33bd5baaee014bb7ae1469e05fbbacb607d3501
SHA256: BF7B79106089D2FD9069C4D92DE88C793E783F43B7DF6D09CBD8B5871BF7ED59
File Size: 9.95 MB, 9954816 bytes
MD5: d5d5fc8de176da1487ba106a90e69b74
SHA1: c207f5d0ce5d1440864c368006d1fbfea8b3c8b6
SHA256: 7629564AE4D62B602A7CFBA072E83E0403C0FA33251CF89FC4421460BA3097FA
File Size: 5.08 MB, 5080794 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has TLS information
  • File is 32-bit executable
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
Show More
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
File Version 1.00
Internal Name TJprojMain
Original Filename TJprojMain.exe
Product Name Project1
Product Version 1.00

File Traits

  • HighEntropy
  • No Version Info
  • x64

Block Information

Similar Families

  • Mimikatz.RD

Files Modified

File Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\_ctypes.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\_multiprocessing.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\_queue.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\_ssl.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\_tkinter.pyd Generic Write,Read Attributes
Show More
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\combo_gui.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\libcrypto-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\libffi-7.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\libssl-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\pyexpat.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\python310.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl86t.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl8\8.4\platform-1.0.18.tm Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl8\8.4\platform\shell-1.1.4.tm Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl8\8.5\msgcat-1.6.1.tm Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl8\8.5\tcltest-2.5.3.tm Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl8\8.6\http-2.9.5.tm Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\auto.tcl Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\clock.tcl Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\encoding\ascii.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\encoding\big5.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\encoding\cns11643.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\encoding\cp1250.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\encoding\cp1251.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\encoding\cp1252.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\encoding\cp1253.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\encoding\cp1254.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\encoding\cp1255.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\encoding\cp1256.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\encoding\cp1257.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\encoding\cp1258.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\encoding\cp437.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\encoding\cp737.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\encoding\cp775.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\encoding\cp850.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\encoding\cp852.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\encoding\cp855.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\encoding\cp857.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\encoding\cp860.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\encoding\cp861.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\encoding\cp862.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\encoding\cp863.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\encoding\cp864.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\encoding\cp865.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\encoding\cp866.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\encoding\cp869.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\encoding\cp874.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\encoding\cp932.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\encoding\cp936.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\encoding\cp949.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\encoding\cp950.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\encoding\dingbats.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\encoding\ebcdic.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\encoding\euc-cn.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\encoding\euc-jp.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\encoding\euc-kr.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\encoding\gb12345.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\encoding\gb1988.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\encoding\gb2312-raw.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\encoding\gb2312.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\encoding\iso2022-jp.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\encoding\iso2022-kr.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\encoding\iso2022.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\encoding\iso8859-1.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\encoding\iso8859-10.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\encoding\iso8859-11.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\encoding\iso8859-13.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\encoding\iso8859-14.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\encoding\iso8859-15.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\encoding\iso8859-16.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\encoding\iso8859-2.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\encoding\iso8859-3.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\encoding\iso8859-4.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\encoding\iso8859-5.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\encoding\iso8859-6.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\encoding\iso8859-7.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\encoding\iso8859-8.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\encoding\iso8859-9.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\encoding\jis0201.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\encoding\jis0208.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\encoding\jis0212.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\encoding\koi8-r.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\encoding\koi8-u.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\encoding\ksc5601.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\encoding\maccenteuro.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\encoding\maccroatian.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\encoding\maccyrillic.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\encoding\macdingbats.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\encoding\macgreek.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\encoding\maciceland.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\encoding\macjapan.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\encoding\macroman.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\encoding\macromania.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\encoding\macthai.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\encoding\macturkish.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\encoding\macukraine.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\encoding\shiftjis.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\encoding\symbol.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\encoding\tis-620.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\history.tcl Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\http1.0\http.tcl Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\http1.0\pkgindex.tcl Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\init.tcl Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\af.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\af_za.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\ar.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\ar_in.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\ar_jo.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\ar_lb.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\ar_sy.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\be.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\bg.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\bn.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\bn_in.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\ca.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\cs.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\da.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\de.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\de_at.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\de_be.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\el.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\en_au.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\en_be.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\en_bw.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\en_ca.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\en_gb.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\en_hk.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\en_ie.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\en_in.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\en_nz.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\en_ph.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\en_sg.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\en_za.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\en_zw.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\eo.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\es.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\es_ar.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\es_bo.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\es_cl.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\es_co.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\es_cr.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\es_do.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\es_ec.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\es_gt.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\es_hn.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\es_mx.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\es_ni.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\es_pa.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\es_pe.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\es_pr.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\es_py.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\es_sv.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\es_uy.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\es_ve.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\et.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\eu.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\eu_es.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\fa.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\fa_in.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\fa_ir.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\fi.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\fo.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\fo_fo.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\fr.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\fr_be.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\fr_ca.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\fr_ch.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\ga.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\ga_ie.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\gl.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\gl_es.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\gv.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\gv_gb.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\he.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\hi.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\hi_in.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\hr.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\hu.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\id.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\id_id.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\is.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\it.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\it_ch.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\ja.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\kl.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\kl_gl.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\ko.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\ko_kr.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\kok.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\kok_in.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\kw.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\kw_gb.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\lt.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\onefile_1072_134083363692427812\tcl\msgs\lv.msg Generic Write,Read Attributes

7195 additional files are not displayed above.

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryInformationProcess
Show More
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWriteFile
  • UNKNOWN
Process Shell Execute
  • CreateProcess
Process Manipulation Evasion
  • NtUnmapViewOfSection
Other Suspicious
  • SetWindowsHookEx

Shell Command Execution

c:\users\user\downloads\55eabcd94a2b2da1b6c4eccdd6691f57f74feacc_0008319488 c:\users\user\downloads\55eabcd94a2b2da1b6c4eccdd6691f57f74feacc_0008319488
c:\users\user\downloads\55eabcd94a2b2da1b6c4eccdd6691f57f74feacc_0008319488 c:\users\user\downloads\55eabcd94a2b2da1b6c4eccdd6691f57f74feacc_0008319488
c:\users\user\downloads\55eabcd94a2b2da1b6c4eccdd6691f57f74feacc_0008319488 c:\users\user\downloads\55eabcd94a2b2da1b6c4eccdd6691f57f74feacc_0008319488
c:\users\user\downloads\27e5ed8f1a4c741c0c3b960d679f8e802b798d48_0007619584 c:\users\user\downloads\27e5ed8f1a4c741c0c3b960d679f8e802b798d48_0007619584
c:\users\user\downloads\f33bd5baaee014bb7ae1469e05fbbacb607d3501_0009954816 c:\users\user\downloads\f33bd5baaee014bb7ae1469e05fbbacb607d3501_0009954816

Trending

Most Viewed

Loading...