Threat Database Trojans Trojan.Filecoder.Python

Trojan.Filecoder.Python

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 9,907
Threat Level: 80 % (High)
Infected Computers: 557
First Seen: November 29, 2022
Last Seen: March 15, 2026
OS(es) Affected: Windows

SpyHunter Detects & Remove Trojan.Filecoder.Python

File System Details

Trojan.Filecoder.Python may create the following file(s):
# File Name MD5 Detections
1. 03437ecbf89f32b3c102297f094f1511f8da91ac54a23d2b076cbf8658f9d3ba.dll 960bd90211156c6140ce40430abd433d 4
2. 09a0caadc4df3d4278368f94f52007894c2b51d3785d985cb8e42646e8a33b68.dll d03848a6760af241d8641f65fbc2f166 4
3. 0accc0347c52f10382b328ab3f74795732f74d9a1636abcd65fc15087df17f71.dll 2becdd067c34f6ec0dd5045603d137d0 4
4. 120cad05c27ce8cb5a5f93559eed4321be6ddeccb4ea760fe77b7ac9792895cf.dll 86471e26ad535e780ed401bb0599310b 4
5. 2d6768d7a20d300a4768ab63b48be977a7faa9e77316bd9bed160ca47a61184a.dll 5576974fdce0117d7ebcaea79a6ff259 4
6. 2d95507aa1ea5d2a6313bc5c201cf76e6aae4c207aa0fafe8f1fcb03e94102ec.dll 25af3ae9f4ebe5413b0ca1080b69b0ca 4
7. 00d832b42a66653d59f642136c7d44d0baa37c05591a1773dfd45880f6e6e5f4.dll 6b894fc38b12c169489d89ef4233ecb0 2
8. 02760a34946e406cd3cad3e56945b0d3f5de324adccd0e95814f85ebb4d7b439.dll 2b9e3fb277d36944e3dab113feddfb3c 2
9. 0a809481eeb607b57343e7b67426c45e2197037024e4e9816e0f28d4ad14cbf9.dll 81eee7fab2fce566920be2a87ea4ee8f 2
10. 0c5c4d858efb8a897715ba623630ba5f528a9787d6cc456d24cf047dc5a62efa.dll ebad7d173423946dec34e04235c68387 2
11. 13f894c8a4cdae73f2d51b05a9d341569339f8da0b9839529f24c7304b48ce6a.dll 109dc1555f5e2e3401620fc3ddfcddb5 2
12. 1521df9c74d826651c61005617c7b5bce8347020456677a8c6818d4e49a666ab.dll 4d25bd8a92d770f7f75a25f816e224f8 2
13. 1539c5ab5c631df582727547d7fd4adabb66424c65bca9049e197833e5737fa6.dll e7a68b408277fd3740093d4621d508f5 2
14. 170fdb3925a301a3a84ee2e2ccc257fe2d5fa600cff92fe42a646b36347d1455.dll 0079a7f64624f620850c6e7c1124c91d 2
15. 17865bac17cbd75f131a9b66f31a9f249e95bd81df5e8ef8d45a26f2e7eb05da.dll 32efb76cb942ef1ca91c398239366563 2
16. 18957a53fd5db0e6ba655840cd091993e564aeff45fcaa02d7a10027a5c7d088.dll 1ab301da5ff25a1254ea98993fcd27ce 2
17. 1b3c69947e9391d95a427de4e3e7c13be6c06455549d16f21560b920d47e356e.dll 8243ea927a43c05393cf694bb836fb5e 2
18. 1fb1e8033692f29836cf73f89fec0fbac8ffb0e32d35cfaf037f16cb647f4106.dll ebe47fcf91371b9123dbf031d651672d 2
19. 2106ab01347d1d61ac9a54a34ea73915d69ea4315ea67c98ea5cba5510de1aba.dll 49e25b74d812d7d5170ff159df2acc2f 2
20. 2422d9a13a4dde705f8ecbe2333dbf4e37aa13ad7b1c90df2aa5111614975dfe.dll 898d24e81acfaf3c5e8a1154ffa0ad5e 2
21. 24af5a0d8d584acf8d583dcb6bbdcc16ed0e806c7caaa4fe7fdbd9c52c208c60.dll 018771edcc3bc4c6c76b307c20aa9ee9 2
22. 24b41ea15d82cb302b3ddff7a74bea2f7c60ee14fc5bba60e604615d06bff408.dll 674377c4665e616a57664e70ea7c5d69 2
23. 25c08ec4934816439866b05351ef62b9f8a6f4df49dc37b619ce8d7707088eec.dll 3eb0194ade891f972d35da4e26654314 2
24. 275fdcc4a303181ec3148b61fc1fdb355d93dd701b32bdc1aa3a5eab83000d4f.dll 2db7fa124bb890a799be0f76f68da27f 2
25. 281a1c1f4588d0e4501bab2b39c483c17f0029faf2c5962b01bf85d1fd80ae2c.dll 4e75de025fe6578cbe69fa96211635dc 2
26. 291ed001c2e996ba0f53b8633b959e5ed19fad33db3ed812d5b6e711cfb3e535.dll 4e5065ebf63e30e938a02b820a9919c1 2
27. 29a47d4681930521a35079ecb0f0dc36cdbb6d16652ba83e8b12561cbd40f661.dll d69235ee612e573c54a0a362dc9c435d 2
28. 2c4db1c97cc767c73d020e6f3671d867aa1f6cc2158a8c09b1d02e97babb90dd.dll bfd1f2ef110191ef1c977cdfc1a60452 2
29. 30f7fb15d5cbfa246e555db68cd3e21aa982e10158cbb08223e0d5e314f893ff.dll 2115f9bfd36e0c8bee27a4db2b7780ce 2
30. 18ed265d7f419a57ee6426260b92aef71e0f498a012afad9ba66ced6769d9953.dll 474e0552c7faa9f2140e872796931488 1
More files

Analysis Report

General information

Family Name: Trojan.Filecoder.Python
Signature status: No Signature

Known Samples

MD5: f960d33bc092c6ef99695ef7b1f85c43
SHA1: f6aba14531b50440058504940efdfa91c78d73e4
SHA256: E1EA8F6CB3F07586C4AADFA943B9D669011201DA2CB19DBBA922BE8223B4DFA9
File Size: 9.27 MB, 9270005 bytes
MD5: b30be297c70cb0d0661942544d8ec6c2
SHA1: a37142c19222c78f9679559b32968eec97fc5771
SHA256: A9AE65860B94B9F9C08A77F8D8A32C2016397B6DB224BF92335126E318BC0EB2
File Size: 1.72 MB, 1723181 bytes
MD5: 48e68d403bbbde303af5f7e3c43ee9e7
SHA1: 92423ebc59e3d54afb47aa6fb0877dccf1523434
SHA256: 544A002C2DD9F86638038D9CBA627A7E268119B48CCB5CB048B128386B6D2839
File Size: 5.82 MB, 5824920 bytes
MD5: 8b85522f9aa52856e0fc4bd040ac54da
SHA1: 620d3a37bd0c34f479a772c15fad3d6f0ba2636a
SHA256: 0972BAD618E59A573D28D7EF32EA03C83988A322AAEAF3534BCA2BDDBB1BB95C
File Size: 8.49 MB, 8490253 bytes
MD5: 2750128763222b4277b1f7f7033e9cc3
SHA1: e509e63014bb15efa94b14827bd689be8725cdd9
SHA256: 95E584C106362B7AA4296FFEEC90844D970B904F7541CE549E17763C29DE4E60
File Size: 7.44 MB, 7444169 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name Microsoft Corporation
File Description Runtime Broker
File Version 10.0.19041.746 (WinBuild.160101.0800)
Internal Name RuntimeBroker.exe
Legal Copyright © Microsoft Corporation. All rights reserved.
Original Filename RuntimeBroker.exe
Product Name Microsoft® Windows® Operating System
Product Version 10.0.19041.746

Block Information

Total Blocks: 820
Potentially Malicious Blocks: 0
Whitelisted Blocks: 820
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 2 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
c:\users\user\appdata\local\temp\_mei14242\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei14242\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei14242\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei14242\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei14242\_queue.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei14242\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei14242\_sqlite3.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei14242\_ssl.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei14242\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei14242\camera Generic Write,Read Attributes
Show More
c:\users\user\appdata\local\temp\_mei14242\config.json Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei14242\getpass Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei14242\injection-obfuscated.js Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei14242\libcrypto-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei14242\libssl-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei14242\pil\_imaging.cp310-win_amd64.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei14242\pil\_imagingcms.cp310-win_amd64.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei14242\pil\_imagingtk.cp310-win_amd64.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei14242\pil\_webp.cp310-win_amd64.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei14242\python310.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei14242\pywin32_system32\pywintypes310.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei14242\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei14242\sqlite3.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei14242\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei14242\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei14242\vcruntime140_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei14242\win32crypt.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\auto.tcl Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\clock.tcl Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\ascii.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\big5.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cns11643.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp1250.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp1251.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp1252.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp1253.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp1254.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp1255.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp1256.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp1257.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp1258.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp437.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp737.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp775.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp850.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp852.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp855.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp857.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp860.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp861.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp862.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp863.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp864.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp865.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp866.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp869.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp874.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp932.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp936.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp949.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp950.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\dingbats.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\ebcdic.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\euc-cn.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei20602\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei20602\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei20602\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei20602\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei20602\_queue.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei20602\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei20602\_sqlite3.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei20602\_ssl.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei20602\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei20602\camera Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei20602\config.json Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei20602\getpass Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei20602\injection-obfuscated.js Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei20602\libcrypto-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei20602\libssl-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei20602\pil\_imaging.cp310-win_amd64.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei20602\pil\_imagingcms.cp310-win_amd64.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei20602\pil\_imagingtk.cp310-win_amd64.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei20602\pil\_webp.cp310-win_amd64.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei20602\python310.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei20602\pywin32_system32\pywintypes310.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei20602\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei20602\sqlite3.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei20602\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei20602\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei20602\vcruntime140_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei20602\win32crypt.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30042\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30042\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30042\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30042\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30042\_queue.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30042\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30042\_sqlite3.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30042\_ssl.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30042\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30042\camera Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30042\config.json Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30042\getpass Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30042\injection-obfuscated.js Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30042\libcrypto-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30042\libssl-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30042\pil\_imaging.cp310-win_amd64.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30042\pil\_imagingcms.cp310-win_amd64.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30042\pil\_imagingtk.cp310-win_amd64.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30042\pil\_webp.cp310-win_amd64.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30042\python310.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30042\pywin32_system32\pywintypes310.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30042\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30042\sqlite3.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30042\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30042\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30042\vcruntime140_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30042\win32crypt.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei33602\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei33602\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei33602\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei33602\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei33602\_queue.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei33602\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei33602\_sqlite3.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei33602\_ssl.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei33602\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei33602\camera Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei33602\config.json Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei33602\getpass Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei33602\injection-obfuscated.js Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei33602\libcrypto-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei33602\libssl-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei33602\pil\_imaging.cp310-win_amd64.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei33602\pil\_imagingcms.cp310-win_amd64.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei33602\pil\_imagingtk.cp310-win_amd64.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei33602\pil\_webp.cp310-win_amd64.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei33602\python310.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei33602\pywin32_system32\pywintypes310.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei33602\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei33602\sqlite3.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei33602\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei33602\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei33602\vcruntime140_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei33602\win32crypt.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei39762\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei39762\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei39762\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei39762\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei39762\_queue.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei39762\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei39762\_sqlite3.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei39762\_ssl.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei39762\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei39762\camera Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei39762\config.json Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei39762\getpass Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei39762\injection-obfuscated.js Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei39762\libcrypto-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei39762\libssl-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei39762\pil\_imaging.cp310-win_amd64.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei39762\pil\_imagingcms.cp310-win_amd64.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei39762\pil\_imagingtk.cp310-win_amd64.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei39762\pil\_webp.cp310-win_amd64.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei39762\python310.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei39762\pywin32_system32\pywintypes310.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei39762\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei39762\sqlite3.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei39762\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei39762\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei39762\vcruntime140_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei39762\win32crypt.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei49842\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei49842\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei49842\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei49842\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei49842\_queue.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei49842\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei49842\_sqlite3.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei49842\_ssl.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei49842\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei49842\camera Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei49842\config.json Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei49842\getpass Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei49842\injection-obfuscated.js Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei49842\libcrypto-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei49842\libssl-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei49842\pil\_imaging.cp310-win_amd64.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei49842\pil\_imagingcms.cp310-win_amd64.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei49842\pil\_imagingtk.cp310-win_amd64.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei49842\pil\_webp.cp310-win_amd64.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei49842\python310.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei49842\pywin32_system32\pywintypes310.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei49842\select.pyd Generic Write,Read Attributes

2293 additional files are not displayed above.

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAddAtomEx
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
Show More
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWriteFile
  • UNKNOWN
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess

Shell Command Execution

c:\users\user\downloads\f6aba14531b50440058504940efdfa91c78d73e4_0009270005 "c:\users\user\downloads\f6aba14531b50440058504940efdfa91c78d73e4_0009270005"
c:\users\user\downloads\620d3a37bd0c34f479a772c15fad3d6f0ba2636a_0008490253 "c:\users\user\downloads\620d3a37bd0c34f479a772c15fad3d6f0ba2636a_0008490253"
c:\users\user\downloads\e509e63014bb15efa94b14827bd689be8725cdd9_0007444169 "c:\users\user\downloads\e509e63014bb15efa94b14827bd689be8725cdd9_0007444169"

Trending

Most Viewed

Loading...