Threat Database Trojans Trojan.KillMBR.O

Trojan.KillMBR.O

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 17,997
Threat Level: 80 % (High)
Infected Computers: 2
First Seen: July 2, 2022
Last Seen: October 6, 2025
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.KillMBR.O
Signature status: No Signature

Known Samples

MD5: f4b186092bedf8bb157c7f957eb1f056
SHA1: ed604b1adf2fc6c51d22e856d35bbb12ebb465f1
SHA256: 587C46B3BDB10E478FFE30462870F4E087A8D9C94FF3B86D48121DC0F910BC55
File Size: 5.70 MB, 5700080 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

File Traits

  • .UPX
  • 2+ executable sections
  • HighEntropy
  • No Version Info
  • packed
  • upx
  • x86

Block Information

Total Blocks: 875
Potentially Malicious Blocks: 0
Whitelisted Blocks: 875
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
c:\users\user\appdata\local\temp\_mei10482\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10482\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10482\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10482\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10482\b.bat Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10482\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10482\libcrypto-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10482\pyarmor_runtime_000000\pyarmor_runtime.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10482\python38.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10482\runb.vbs Generic Write,Read Attributes
Show More
c:\users\user\appdata\local\temp\_mei10482\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10482\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10482\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10482\win.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei13882\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei13882\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei13882\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei13882\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei13882\b.bat Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei13882\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei13882\libcrypto-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei13882\pyarmor_runtime_000000\pyarmor_runtime.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei13882\python38.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei13882\runb.vbs Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei13882\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei13882\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei13882\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei13882\win.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei1642\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei1642\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei1642\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei1642\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei1642\b.bat Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei1642\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei1642\libcrypto-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei1642\pyarmor_runtime_000000\pyarmor_runtime.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei1642\python38.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei1642\runb.vbs Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei1642\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei1642\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei1642\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei1642\win.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17602\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17602\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17602\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17602\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17602\b.bat Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17602\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17602\libcrypto-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17602\pyarmor_runtime_000000\pyarmor_runtime.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17602\python38.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17602\runb.vbs Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17602\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17602\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17602\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17602\win.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei20762\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei20762\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei20762\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei20762\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei20762\b.bat Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei20762\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei20762\libcrypto-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei20762\pyarmor_runtime_000000\pyarmor_runtime.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei20762\python38.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei20762\runb.vbs Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei20762\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei20762\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei20762\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei20762\win.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei23562\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei23562\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei23562\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei23562\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei23562\b.bat Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei23562\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei23562\libcrypto-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei23562\pyarmor_runtime_000000\pyarmor_runtime.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei23562\python38.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei23562\runb.vbs Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei23562\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei23562\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei23562\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei23562\win.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei26282\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei26282\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei26282\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei26282\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei26282\b.bat Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei26282\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei26282\libcrypto-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei26282\pyarmor_runtime_000000\pyarmor_runtime.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei26282\python38.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei26282\runb.vbs Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei26282\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei26282\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei26282\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei26282\win.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei27602\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei27602\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei27602\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei27602\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei27602\b.bat Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei27602\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei27602\libcrypto-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei27602\pyarmor_runtime_000000\pyarmor_runtime.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei27602\python38.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei27602\runb.vbs Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei27602\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei27602\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei27602\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei27602\win.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30162\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30162\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30162\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30162\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30162\b.bat Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30162\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30162\libcrypto-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30162\pyarmor_runtime_000000\pyarmor_runtime.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30162\python38.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30162\runb.vbs Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30162\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30162\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30162\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei30162\win.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei37042\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei37042\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei37042\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei37042\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei37042\b.bat Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei37042\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei37042\libcrypto-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei37042\pyarmor_runtime_000000\pyarmor_runtime.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei37042\python38.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei37042\runb.vbs Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei37042\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei37042\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei37042\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei37042\win.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei39322\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei39322\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei39322\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei39322\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei39322\b.bat Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei39322\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei39322\libcrypto-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei39322\pyarmor_runtime_000000\pyarmor_runtime.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei39322\python38.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei39322\runb.vbs Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei39322\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei39322\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei39322\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei39322\win.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei39522\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei39522\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei39522\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei39522\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei39522\b.bat Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei39522\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei39522\libcrypto-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei39522\pyarmor_runtime_000000\pyarmor_runtime.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei39522\python38.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei39522\runb.vbs Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei39522\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei39522\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei39522\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei39522\win.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei41722\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei41722\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei41722\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei41722\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei41722\b.bat Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei41722\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei41722\libcrypto-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei41722\pyarmor_runtime_000000\pyarmor_runtime.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei41722\python38.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei41722\runb.vbs Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei41722\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei41722\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei41722\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei41722\win.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei45122\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei45122\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei45122\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei45122\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei45122\b.bat Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei45122\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei45122\libcrypto-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei45122\pyarmor_runtime_000000\pyarmor_runtime.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei45122\python38.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei45122\runb.vbs Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei45122\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei45122\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei45122\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei45122\win.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei46082\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei46082\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei46082\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei46082\_socket.pyd Generic Write,Read Attributes

60 additional files are not displayed above.

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
Show More
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetMessage
  • win32u.dll!NtUserGetProp
  • win32u.dll!NtUserGetThreadState
  • win32u.dll!NtUserPeekMessage
  • win32u.dll!NtUserPostMessage
  • win32u.dll!NtUserShowWindow
Process Shell Execute
  • CreateProcess

Shell Command Execution

c:\users\user\downloads\ed604b1adf2fc6c51d22e856d35bbb12ebb465f1_0005700080 "c:\users\user\downloads\ed604b1adf2fc6c51d22e856d35bbb12ebb465f1_0005700080"
c:\users\user\downloads\ed604b1adf2fc6c51d22e856d35bbb12ebb465f1_0005700080 "c:\users\user\downloads\ed604b1adf2fc6c51d22e856d35bbb12ebb465f1_0005700080"
c:\users\user\downloads\ed604b1adf2fc6c51d22e856d35bbb12ebb465f1_0005700080 "c:\users\user\downloads\ed604b1adf2fc6c51d22e856d35bbb12ebb465f1_0005700080"
c:\users\user\downloads\ed604b1adf2fc6c51d22e856d35bbb12ebb465f1_0005700080 "c:\users\user\downloads\ed604b1adf2fc6c51d22e856d35bbb12ebb465f1_0005700080"
c:\users\user\downloads\ed604b1adf2fc6c51d22e856d35bbb12ebb465f1_0005700080 "c:\users\user\downloads\ed604b1adf2fc6c51d22e856d35bbb12ebb465f1_0005700080"
Show More
c:\users\user\downloads\ed604b1adf2fc6c51d22e856d35bbb12ebb465f1_0005700080 "c:\users\user\downloads\ed604b1adf2fc6c51d22e856d35bbb12ebb465f1_0005700080"
c:\users\user\downloads\ed604b1adf2fc6c51d22e856d35bbb12ebb465f1_0005700080 "c:\users\user\downloads\ed604b1adf2fc6c51d22e856d35bbb12ebb465f1_0005700080"
c:\users\user\downloads\ed604b1adf2fc6c51d22e856d35bbb12ebb465f1_0005700080 "c:\users\user\downloads\ed604b1adf2fc6c51d22e856d35bbb12ebb465f1_0005700080"
c:\users\user\downloads\ed604b1adf2fc6c51d22e856d35bbb12ebb465f1_0005700080 "c:\users\user\downloads\ed604b1adf2fc6c51d22e856d35bbb12ebb465f1_0005700080"
c:\users\user\downloads\ed604b1adf2fc6c51d22e856d35bbb12ebb465f1_0005700080 "c:\users\user\downloads\ed604b1adf2fc6c51d22e856d35bbb12ebb465f1_0005700080"
c:\users\user\downloads\ed604b1adf2fc6c51d22e856d35bbb12ebb465f1_0005700080 "c:\users\user\downloads\ed604b1adf2fc6c51d22e856d35bbb12ebb465f1_0005700080"
c:\users\user\downloads\ed604b1adf2fc6c51d22e856d35bbb12ebb465f1_0005700080 "c:\users\user\downloads\ed604b1adf2fc6c51d22e856d35bbb12ebb465f1_0005700080"
c:\users\user\downloads\ed604b1adf2fc6c51d22e856d35bbb12ebb465f1_0005700080 "c:\users\user\downloads\ed604b1adf2fc6c51d22e856d35bbb12ebb465f1_0005700080"
c:\users\user\downloads\ed604b1adf2fc6c51d22e856d35bbb12ebb465f1_0005700080 "c:\users\user\downloads\ed604b1adf2fc6c51d22e856d35bbb12ebb465f1_0005700080"
c:\users\user\downloads\ed604b1adf2fc6c51d22e856d35bbb12ebb465f1_0005700080 "c:\users\user\downloads\ed604b1adf2fc6c51d22e856d35bbb12ebb465f1_0005700080"
c:\users\user\downloads\ed604b1adf2fc6c51d22e856d35bbb12ebb465f1_0005700080 "c:\users\user\downloads\ed604b1adf2fc6c51d22e856d35bbb12ebb465f1_0005700080"
c:\users\user\downloads\ed604b1adf2fc6c51d22e856d35bbb12ebb465f1_0005700080 "c:\users\user\downloads\ed604b1adf2fc6c51d22e856d35bbb12ebb465f1_0005700080"
c:\users\user\downloads\ed604b1adf2fc6c51d22e856d35bbb12ebb465f1_0005700080 "c:\users\user\downloads\ed604b1adf2fc6c51d22e856d35bbb12ebb465f1_0005700080"

Trending

Most Viewed

Loading...