Threat Database Trojans Trojan.Fonix.K

Trojan.Fonix.K

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 1,046
Threat Level: 80 % (High)
Infected Computers: 4,277
First Seen: October 25, 2021
Last Seen: April 8, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.Fonix.K
Signature status: No Signature

Known Samples

MD5: 6622989b16ec8c65828c28c3db3d2f5d
SHA1: 7e7bb39e8cdec9b2cd3dcc2945fbd9c9caab49c4
SHA256: 1E3442E937522A54C03AA5311472B3E86699A1F67C6598D33B2C1ACB0840300F
File Size: 4.33 MB, 4325376 bytes
MD5: db00d147cbc83a3e057b442648600abd
SHA1: 723602f4b92c9d80344701147eb5d7aada215c2c
SHA256: 4100FA1ABA3649193521DE7A84D96C07BFBC6A423C25D9306B8CE4EDED7B1A7D
File Size: 7.20 MB, 7200431 bytes
MD5: 776a5506602df36dd4f25095f7bb3c6d
SHA1: 0e74c0cca9065dab793dddf553565dabf2a14fc3
SHA256: 8B9B582CC3C4B2C352D3F525733CC4A76F8F1090160D07842D3C581822F91F5F
File Size: 2.42 MB, 2420736 bytes
MD5: ddfea43eed83a9f1487b89a7fc6173af
SHA1: 4ea4146c5ff00266f6ad9efb468952999aa6e4b4
SHA256: 79055213BE0509F23C9F95CB1358D3D2729E10E10001D041B0C5B362F68F51C5
File Size: 6.84 MB, 6844015 bytes
MD5: e85c117bb681828b971a16c73f8c7c40
SHA1: e925183f9c77ba07260e53f2f0dc65ce3a16e27e
SHA256: E5265746533C203AA1925186C942309CD147F60422C7C3A0160AC88BFE2241A9
File Size: 324.00 KB, 324000 bytes
Show More
MD5: 850e58508222606f1aaa4577e2c6e5cb
SHA1: 4ef435a64c92594fbd033d7fda10bb480bc00057
SHA256: 6E8FA67F59C66AE3BC342D4D51BA93E6F8C61630FD49F8D3E6383654D68393BA
File Size: 3.36 MB, 3358720 bytes
MD5: 44975859a59418f18a98adf69efebef7
SHA1: e2b86447946ebbcec2eb766b61348d458e0b24bc
SHA256: 21D6D8111B1BD58DE47504A2DECEE6D76CB6428407C8612C85338BBCCE638B78
File Size: 1.86 MB, 1860000 bytes
MD5: 10d8af5309bce3b6bdcb7d45eb7569de
SHA1: 0d66839b5c19dcda37d809e2387300fb0e0721ae
SHA256: EA03A471F9E70FA9937FE280B7B964B8A1EF42E11A04695D1A30DE0AD686E3D6
File Size: 1.79 MB, 1791658 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

File Traits

  • 2+ executable sections
  • big overlay
  • HighEntropy
  • No Version Info
  • Py-installer
  • x64
  • zlib (In Overlay)
  • zlib overlay

Block Information

Total Blocks: 696
Potentially Malicious Blocks: 0
Whitelisted Blocks: 696
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
c:\users\user\appdata\local\temp\_mei10682\_asyncio.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\_ctypes.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\_multiprocessing.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\_overlapped.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\_queue.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\_socket.pyd Generic Write,Read Attributes
Show More
c:\users\user\appdata\local\temp\_mei10682\_ssl.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\durellodivinomylove.exe.manifest Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\libcrypto-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\libffi-7.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\libssl-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\pyexpat.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\python39.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16642\_asyncio.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16642\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16642\_ctypes.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16642\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16642\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16642\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16642\_multiprocessing.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16642\_overlapped.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16642\_queue.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16642\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16642\_ssl.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16642\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16642\durellodivinomylove.exe.manifest Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16642\libcrypto-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16642\libffi-7.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16642\libssl-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16642\pyexpat.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16642\python39.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16642\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16642\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei16642\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17162\_asyncio.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17162\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17162\_ctypes.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17162\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17162\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17162\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17162\_multiprocessing.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17162\_overlapped.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17162\_queue.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17162\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17162\_ssl.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17162\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17162\durellodivinomylove.exe.manifest Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17162\libcrypto-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17162\libffi-7.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17162\libssl-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17162\pyexpat.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17162\python39.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17162\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17162\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17162\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30162\_asyncio.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30162\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30162\_ctypes.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30162\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30162\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30162\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30162\_multiprocessing.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30162\_overlapped.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30162\_queue.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30162\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30162\_ssl.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30162\durellodivinomylove.exe.manifest Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30162\libcrypto-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30162\libffi-7.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30162\libssl-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30162\pyexpat.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30162\python39.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30162\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30162\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30682\_asyncio.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30682\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30682\_ctypes.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30682\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30682\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30682\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30682\_multiprocessing.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30682\_overlapped.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30682\_queue.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30682\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30682\_ssl.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30682\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30682\durellodivinomylove.exe.manifest Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30682\libcrypto-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30682\libffi-7.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30682\libssl-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30682\pyexpat.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30682\python39.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30682\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30682\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30682\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35882\_asyncio.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35882\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35882\_ctypes.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35882\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35882\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35882\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35882\_multiprocessing.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35882\_overlapped.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35882\_queue.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35882\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35882\_ssl.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35882\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35882\durellodivinomylove.exe.manifest Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35882\libcrypto-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35882\libffi-7.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35882\libssl-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35882\pyexpat.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35882\python39.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35882\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35882\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35882\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei36002\_asyncio.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei36002\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei36002\_ctypes.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei36002\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei36002\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei36002\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei36002\_multiprocessing.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei36002\_overlapped.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei36002\_queue.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei36002\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei36002\_ssl.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei36002\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei36002\durellodivinomylove.exe.manifest Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei36002\libcrypto-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei36002\libffi-7.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei36002\libssl-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei36002\pyexpat.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei36002\python39.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei36002\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei36002\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei36002\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei4882\_asyncio.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei4882\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei4882\_ctypes.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei4882\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei4882\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei4882\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei4882\_multiprocessing.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei4882\_overlapped.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei4882\_queue.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei4882\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei4882\_ssl.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei4882\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei4882\durellodivinomylove.exe.manifest Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei4882\libcrypto-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei4882\libffi-7.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei4882\libssl-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei4882\pyexpat.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei4882\python39.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei4882\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei4882\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei4882\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei49242\_asyncio.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei49242\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei49242\_ctypes.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei49242\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei49242\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei49242\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei49242\_multiprocessing.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei49242\_overlapped.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei49242\_queue.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei49242\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei49242\_ssl.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei49242\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei49242\durellodivinomylove.exe.manifest Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei49242\libcrypto-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei49242\libffi-7.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei49242\libssl-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei49242\pyexpat.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei49242\python39.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei49242\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei49242\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei49242\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei5202\_asyncio.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei5202\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei5202\_ctypes.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei5202\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei5202\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei5202\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei5202\_multiprocessing.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei5202\_overlapped.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei5202\_queue.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei5202\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei5202\_ssl.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei5202\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei5202\durellodivinomylove.exe.manifest Generic Write,Read Attributes

134 additional files are not displayed above.

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
Show More
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • UNKNOWN
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetThreadState
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess

Shell Command Execution

c:\users\user\downloads\4ea4146c5ff00266f6ad9efb468952999aa6e4b4_0006844015 "c:\users\user\downloads\4ea4146c5ff00266f6ad9efb468952999aa6e4b4_0006844015"

Trending

Most Viewed

Loading...