Threat Database Trojans Trojan.Fonix.K

Trojan.Fonix.K

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 1,448
Threat Level: 80 % (High)
Infected Computers: 4,477
First Seen: October 25, 2021
Last Seen: July 20, 2026
OS(es) Affected: Windows

The detection of Trojan.Fonix.K on your system indicates a potential security threat that requires immediate attention. This report provides an overview of the threat, its operating mechanisms, symptoms of infection, and steps to remove it from your system. It's essential to address this issue promptly to prevent potential damage to your data and system integrity.

What Is Trojan.Fonix.K?

Trojan.Fonix.K is identified as a Trojan-type threat, which is a broad category of malware designed to deceive users into installing it on their systems. Trojans often disguise themselves as legitimate software or attach to other programs, allowing them to bypass security measures. Once installed, they can cause a variety of problems, including data theft, system crashes, and the installation of additional malware.

How Trojan.Fonix.K Operates

Like other Trojans, Trojan.Fonix.K is likely designed to operate stealthily, attempting to evade detection by security software. It may exploit vulnerabilities in the operating system or other applications to gain unauthorized access and control. The specific mechanisms and goals of Trojan.Fonix.K can vary, but common actions include data exfiltration, keystroke logging, and the deployment of ransomware or other types of malware.

Symptoms of Infection

Symptoms of a Trojan.Fonix.K infection can be subtle and may not always be immediately apparent. Common indicators of a Trojan infection include unexpected system crashes, slow performance, unusual network activity, and the appearance of unwanted programs or toolbars in your web browser. Additionally, you might notice that your system settings have been changed without your consent, or that your personal files are being encrypted by ransomware.

  • Unexplained changes in system settings or performance
  • Appearance of unfamiliar programs or browser extensions
  • Increased network activity when no applications are running
  • Difficulty in accessing personal files due to encryption

How to Remove Trojan.Fonix.K

  1. Boot your system in Safe Mode with Networking to limit the malware's ability to interfere with the removal process.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system. This can help identify and remove all components of the Trojan.
  3. Uninstall any suspicious programs or applications that you do not recognize or no longer need.
  4. Reset your web browsers (Chrome, Firefox, Edge) to their default settings to remove any malicious extensions or settings changes.
  5. Reboot your system and perform another full scan with your anti-malware tool to ensure that all traces of the Trojan have been removed.

Conclusion

Removing Trojan.Fonix.K from your system requires careful and thorough action to ensure that all components of the malware are eliminated. By following the steps outlined in this report and maintaining vigilant security practices, you can help protect your system and data from future threats. Regularly updating your operating system and applications, using strong antivirus software, and being cautious when downloading and installing programs can significantly reduce the risk of malware infections.

Analysis Report

General information

Family Name: Trojan.Fonix.K
Signature status: No Signature

Known Samples

MD5: 6622989b16ec8c65828c28c3db3d2f5d
SHA1: 7e7bb39e8cdec9b2cd3dcc2945fbd9c9caab49c4
SHA256: 1E3442E937522A54C03AA5311472B3E86699A1F67C6598D33B2C1ACB0840300F
File Size: 4.33 MB, 4325376 bytes
MD5: db00d147cbc83a3e057b442648600abd
SHA1: 723602f4b92c9d80344701147eb5d7aada215c2c
SHA256: 4100FA1ABA3649193521DE7A84D96C07BFBC6A423C25D9306B8CE4EDED7B1A7D
File Size: 7.20 MB, 7200431 bytes
MD5: 776a5506602df36dd4f25095f7bb3c6d
SHA1: 0e74c0cca9065dab793dddf553565dabf2a14fc3
SHA256: 8B9B582CC3C4B2C352D3F525733CC4A76F8F1090160D07842D3C581822F91F5F
File Size: 2.42 MB, 2420736 bytes
MD5: ddfea43eed83a9f1487b89a7fc6173af
SHA1: 4ea4146c5ff00266f6ad9efb468952999aa6e4b4
SHA256: 79055213BE0509F23C9F95CB1358D3D2729E10E10001D041B0C5B362F68F51C5
File Size: 6.84 MB, 6844015 bytes
MD5: e85c117bb681828b971a16c73f8c7c40
SHA1: e925183f9c77ba07260e53f2f0dc65ce3a16e27e
SHA256: E5265746533C203AA1925186C942309CD147F60422C7C3A0160AC88BFE2241A9
File Size: 324.00 KB, 324000 bytes
Show More
MD5: 850e58508222606f1aaa4577e2c6e5cb
SHA1: 4ef435a64c92594fbd033d7fda10bb480bc00057
SHA256: 6E8FA67F59C66AE3BC342D4D51BA93E6F8C61630FD49F8D3E6383654D68393BA
File Size: 3.36 MB, 3358720 bytes
MD5: 44975859a59418f18a98adf69efebef7
SHA1: e2b86447946ebbcec2eb766b61348d458e0b24bc
SHA256: 21D6D8111B1BD58DE47504A2DECEE6D76CB6428407C8612C85338BBCCE638B78
File Size: 1.86 MB, 1860000 bytes
MD5: 10d8af5309bce3b6bdcb7d45eb7569de
SHA1: 0d66839b5c19dcda37d809e2387300fb0e0721ae
SHA256: EA03A471F9E70FA9937FE280B7B964B8A1EF42E11A04695D1A30DE0AD686E3D6
File Size: 1.79 MB, 1791658 bytes
MD5: 7541cd53c393a1255cacc0c8abc219f0
SHA1: 8619929355c15ed670cc031a5d497833974f6e15
SHA256: B4D81941A084214E0A36280EBD81EECCC0ED1989020CD5AD8655A8B53A69F2B6
File Size: 6.20 MB, 6202680 bytes
MD5: 787762650927a660ec32c1db4f3b917b
SHA1: 9401d6286349abdb7ed43c767ff218e7aa5f16c9
SHA256: 522B511809A0DB7DB0917AA51F9D17EC4101F63B75E70D265788A4120AFA30B8
File Size: 5.80 MB, 5804184 bytes
MD5: 758dbc2ced64c50da4db2ba60276f5b8
SHA1: 175ad27fb31350f54813620a7fb7693fa30b61dd
SHA256: 558FC7423BDE39E56CC219D874205B9E20F55A160455101ED87D0BF191D54098
File Size: 3.30 MB, 3303718 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Digital Signatures

Signer Root Status
Hangzhou Shunwang Technology Co.,Ltd DigiCert Trusted Root G4 Root Not Trusted

File Traits

  • 2+ executable sections
  • big overlay
  • HighEntropy
  • No Version Info
  • Py-installer
  • x64
  • zlib (In Overlay)
  • zlib overlay

Block Information

Total Blocks: 696
Potentially Malicious Blocks: 0
Whitelisted Blocks: 696
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
c:\users\user\appdata\local\temp\_mei101762\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei101762\_ctypes.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei101762\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei101762\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei101762\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei101762\_ssl.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei101762\_win32sysloader.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei101762\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei101762\clientconfig.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei101762\libcrypto-1_1.dll Generic Write,Read Attributes
Show More
c:\users\user\appdata\local\temp\_mei101762\libssl-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei101762\pyexpat.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei101762\python37.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei101762\pywintypes37.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei101762\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei101762\setaudio.exe.manifest Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei101762\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei101762\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei101762\vcruntime140_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei101762\volumeset_x64.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei101762\win32api.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei101762\win32file.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\_asyncio.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\_ctypes.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\_multiprocessing.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\_overlapped.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\_queue.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\_ssl.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\durellodivinomylove.exe.manifest Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\libcrypto-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\libffi-7.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\libssl-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\pyexpat.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\python39.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16642\_asyncio.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16642\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16642\_ctypes.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16642\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16642\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16642\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16642\_multiprocessing.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16642\_overlapped.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16642\_queue.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16642\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16642\_ssl.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16642\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16642\durellodivinomylove.exe.manifest Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16642\libcrypto-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16642\libffi-7.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16642\libssl-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16642\pyexpat.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16642\python39.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16642\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16642\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16642\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17162\_asyncio.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17162\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17162\_ctypes.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17162\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17162\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17162\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17162\_multiprocessing.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17162\_overlapped.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17162\_queue.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17162\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17162\_ssl.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17162\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17162\durellodivinomylove.exe.manifest Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17162\libcrypto-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17162\libffi-7.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17162\libssl-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17162\pyexpat.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17162\python39.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17162\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17162\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17162\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei20522\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei20522\_ctypes.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei20522\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei20522\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei20522\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei20522\_ssl.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei20522\_win32sysloader.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei20522\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei20522\clientconfig.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei20522\libcrypto-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei20522\libssl-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei20522\pyexpat.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei20522\python37.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei20522\pywintypes37.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei20522\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei20522\setaudio.exe.manifest Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei20522\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei20522\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei20522\vcruntime140_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei20522\volumeset_x64.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei20522\win32api.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei20522\win32file.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30162\_asyncio.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30162\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30162\_ctypes.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30162\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30162\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30162\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30162\_multiprocessing.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30162\_overlapped.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30162\_queue.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30162\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30162\_ssl.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30162\durellodivinomylove.exe.manifest Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30162\libcrypto-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30162\libffi-7.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30162\libssl-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30162\pyexpat.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30162\python39.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30162\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30162\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30682\_asyncio.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30682\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30682\_ctypes.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30682\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30682\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30682\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30682\_multiprocessing.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30682\_overlapped.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30682\_queue.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30682\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30682\_ssl.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30682\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30682\durellodivinomylove.exe.manifest Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30682\libcrypto-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30682\libffi-7.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30682\libssl-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30682\pyexpat.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30682\python39.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30682\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30682\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30682\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35882\_asyncio.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35882\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35882\_ctypes.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35882\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35882\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35882\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35882\_multiprocessing.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35882\_overlapped.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35882\_queue.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35882\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35882\_ssl.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35882\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35882\durellodivinomylove.exe.manifest Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35882\libcrypto-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35882\libffi-7.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35882\libssl-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35882\pyexpat.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35882\python39.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35882\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35882\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35882\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei36002\_asyncio.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei36002\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei36002\_ctypes.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei36002\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei36002\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei36002\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei36002\_multiprocessing.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei36002\_overlapped.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei36002\_queue.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei36002\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei36002\_ssl.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei36002\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei36002\durellodivinomylove.exe.manifest Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei36002\libcrypto-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei36002\libffi-7.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei36002\libssl-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei36002\pyexpat.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei36002\python39.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei36002\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei36002\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei36002\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei4362\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei4362\_ctypes.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei4362\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei4362\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei4362\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei4362\_ssl.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei4362\_win32sysloader.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei4362\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei4362\clientconfig.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei4362\libcrypto-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei4362\libssl-1_1.dll Generic Write,Read Attributes

420 additional files are not displayed above.

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
Show More
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • UNKNOWN
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetThreadState
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess

Shell Command Execution

c:\users\user\downloads\4ea4146c5ff00266f6ad9efb468952999aa6e4b4_0006844015 "c:\users\user\downloads\4ea4146c5ff00266f6ad9efb468952999aa6e4b4_0006844015"
c:\users\user\downloads\8619929355c15ed670cc031a5d497833974f6e15_0006202680 "c:\users\user\downloads\8619929355c15ed670cc031a5d497833974f6e15_0006202680"

Trending

Most Viewed

Loading...