Threat Database Trojans Trojan.Kryptik.YKAG

Trojan.Kryptik.YKAG

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 19,371
Threat Level: 80 % (High)
Infected Computers: 121
First Seen: May 29, 2024
Last Seen: June 23, 2026
OS(es) Affected: Windows

The detection of Trojan.Kryptik.YKAG on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to compromise the security and integrity of your computer, putting your personal data and sensitive information at risk. It is essential to understand the nature of this threat and take prompt action to remove it and prevent future infections.

What Is Trojan.Kryptik.YKAG?

Trojan.Kryptik.YKAG is a type of Trojan horse malware that can sneak into your system without your knowledge or consent. Trojans are malicious programs that disguise themselves as legitimate software, allowing them to bypass security measures and gain unauthorized access to your computer. Once inside, they can cause a range of problems, from stealing sensitive information to disrupting system performance.

How Trojan.Kryptik.YKAG Operates

Trojan.Kryptik.YKAG, like other Trojans, operates by exploiting vulnerabilities in your system or tricking you into installing it. It may arrive as an email attachment, a downloaded file, or a drive-by download from a compromised website. Once installed, it can communicate with its creators, allowing them to control your computer remotely, steal data, or install additional malware. The specific actions of Trojan.Kryptik.YKAG can vary, but its primary goal is to compromise your system's security and your privacy.

Symptoms of Infection

Identifying a Trojan infection can be challenging, as these malware types are designed to remain hidden. However, there are several symptoms that may indicate your system is infected with Trojan.Kryptik.YKAG or similar malware. These include unusual system behavior, such as unexpected pop-ups, slow performance, or unfamiliar programs running in the background. You might also notice changes in your browser settings or the presence of unfamiliar toolbars. If you suspect your system is infected, it's crucial to act quickly to minimize potential damage.

How to Remove Trojan.Kryptik.YKAG

  1. Enter Safe Mode with Networking to prevent the malware from interfering with the removal process. This mode allows you to use the internet while limiting the malware's ability to run.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter. Ensure the tool is updated to detect the latest threats, including Trojan.Kryptik.YKAG.
  3. Uninstall any suspicious programs or applications that you do not recognize or no longer need. Be cautious, as some malware may disguise itself as legitimate software.
  4. Reset your web browsers, such as Chrome, Firefox, or Edge, to their default settings. This can help remove any malicious extensions or settings changes made by the Trojan.
  5. Reboot your system and perform another scan to ensure that the malware has been completely removed. This step is crucial to verify that no remnants of the malware remain on your system.

Conclusion

Removing Trojan.Kryptik.YKAG requires careful and immediate action to protect your system and data. By understanding how Trojans operate and following the steps outlined above, you can effectively remove this malware and reduce the risk of future infections. It's also essential to maintain good cybersecurity practices, including keeping your operating system and software up to date, using strong antivirus software, and being cautious when downloading files or clicking on links from unknown sources. By taking these precautions, you can significantly enhance your system's security and safeguard your personal information.

Analysis Report

General information

Family Name: Trojan.Kryptik.YKAG
Signature status: No Signature

Known Samples

MD5: 0641701c74849e113d1c2a0c2a264cdc
SHA1: 1181d06189751b1872d77d9c2ef93557a370cf61
SHA256: 3BF688AF8F907772FB8441CEAF6B3C0DD90E8E0AFA2E27138B9CAA0CAC6FA912
File Size: 2.31 MB, 2314240 bytes
MD5: 17296ab2df654c246919b2b485b2d604
SHA1: 998f37be3f7dfa6439ad0573a34074355722ba90
SHA256: CCABE86FB0BB73977478539D5311F51A6C64468D8CD54C74D7EC99956C010B69
File Size: 6.74 MB, 6738610 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version 1.0.0.0
Company Name Katiusha
File Description Katiusha
File Version 1.0.0.0
Internal Name Katiusha.dll
Original Filename Katiusha.dll
Product Name Katiusha
Product Version 1.0.0

File Traits

  • 2+ executable sections
  • dll
  • HighEntropy
  • VirtualAllocExNuma
  • x64

Block Information

Total Blocks: 709
Potentially Malicious Blocks: 0
Whitelisted Blocks: 709
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.DFCF
  • Agent.FGDS
  • AgentTesla.P
  • Filecoder.XI
  • Kryptik.YKAC
Show More
  • XLoader.A

Files Modified

File Attributes
c:\users\user\appdata\local\temp\_mei11962\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11962\bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11962\data.exe.manifest Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11962\microsoft.vc90.crt.manifest Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11962\mpc\glib-2.0-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11962\mpc\gmodule-2.0-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11962\mpc\iconv-2.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11962\mpc\intl-8.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11962\mpc\jfk.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11962\mpc\msvcp144.dll Generic Write,Read Attributes
Show More
c:\users\user\appdata\local\temp\_mei11962\mpc\pcre2-8.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11962\mpc\x.bat Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11962\mpc\zlib-ng2.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11962\msvcm90.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11962\msvcp90.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11962\msvcr90.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11962\python27.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11962\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11962\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei21962\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei21962\bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei21962\data.exe.manifest Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei21962\microsoft.vc90.crt.manifest Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei21962\mpc\glib-2.0-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei21962\mpc\gmodule-2.0-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei21962\mpc\iconv-2.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei21962\mpc\intl-8.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei21962\mpc\jfk.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei21962\mpc\msvcp144.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei21962\mpc\pcre2-8.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei21962\mpc\x.bat Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei21962\mpc\zlib-ng2.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei21962\msvcm90.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei21962\msvcp90.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei21962\msvcr90.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei21962\python27.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei21962\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei21962\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei25162\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei25162\bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei25162\data.exe.manifest Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei25162\microsoft.vc90.crt.manifest Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei25162\mpc\glib-2.0-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei25162\mpc\gmodule-2.0-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei25162\mpc\iconv-2.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei25162\mpc\intl-8.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei25162\mpc\jfk.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei25162\mpc\msvcp144.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei25162\mpc\pcre2-8.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei25162\mpc\x.bat Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei25162\mpc\zlib-ng2.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei25162\msvcm90.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei25162\msvcp90.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei25162\msvcr90.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei25162\python27.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei25162\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei25162\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei31482\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei31482\bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei31482\data.exe.manifest Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei31482\microsoft.vc90.crt.manifest Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei31482\mpc\glib-2.0-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei31482\mpc\gmodule-2.0-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei31482\mpc\iconv-2.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei31482\mpc\intl-8.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei31482\mpc\jfk.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei31482\mpc\msvcp144.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei31482\mpc\pcre2-8.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei31482\mpc\x.bat Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei31482\mpc\zlib-ng2.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei31482\msvcm90.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei31482\msvcp90.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei31482\msvcr90.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei31482\python27.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei31482\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei31482\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei36242\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei36242\bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei36242\data.exe.manifest Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei36242\microsoft.vc90.crt.manifest Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei36242\msvcm90.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei36242\msvcp90.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei42042\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei42042\bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei42042\data.exe.manifest Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei42042\microsoft.vc90.crt.manifest Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei42042\mpc\glib-2.0-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei42042\mpc\gmodule-2.0-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei42042\mpc\iconv-2.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei42042\mpc\intl-8.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei42042\mpc\jfk.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei42042\mpc\msvcp144.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei42042\mpc\pcre2-8.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei42042\mpc\x.bat Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei42042\mpc\zlib-ng2.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei42042\msvcm90.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei42042\msvcp90.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei42042\msvcr90.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei42042\python27.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei42042\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei42042\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei42162\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei42162\bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei42162\data.exe.manifest Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei42162\microsoft.vc90.crt.manifest Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei42162\mpc\glib-2.0-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei42162\mpc\gmodule-2.0-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei42162\mpc\iconv-2.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei42162\mpc\intl-8.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei42162\mpc\jfk.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei42162\mpc\msvcp144.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei42162\mpc\pcre2-8.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei42162\mpc\x.bat Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei42162\mpc\zlib-ng2.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei42162\msvcm90.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei42162\msvcp90.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei42162\msvcr90.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei42162\python27.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei42162\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei42162\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei47242\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei47242\bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei47242\data.exe.manifest Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei47242\microsoft.vc90.crt.manifest Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei47242\mpc\glib-2.0-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei47242\mpc\gmodule-2.0-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei47242\mpc\iconv-2.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei47242\mpc\intl-8.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei47242\mpc\jfk.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei47242\mpc\msvcp144.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei47242\mpc\pcre2-8.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei47242\mpc\x.bat Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei47242\mpc\zlib-ng2.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei47242\msvcm90.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei47242\msvcp90.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei47242\msvcr90.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei47242\python27.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei47242\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei47242\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei56082\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei56082\bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei56082\data.exe.manifest Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei56082\microsoft.vc90.crt.manifest Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei56082\mpc\glib-2.0-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei56082\mpc\gmodule-2.0-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei56082\mpc\iconv-2.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei56082\mpc\intl-8.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei56082\mpc\jfk.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei56082\mpc\msvcp144.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei56082\mpc\pcre2-8.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei56082\mpc\x.bat Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei56082\mpc\zlib-ng2.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei56082\msvcm90.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei56082\msvcp90.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei56082\msvcr90.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei56082\python27.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei56082\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei56082\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei63322\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei63322\bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei63322\data.exe.manifest Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei63322\microsoft.vc90.crt.manifest Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei63322\mpc\glib-2.0-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei63322\mpc\gmodule-2.0-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei63322\mpc\iconv-2.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei63322\mpc\intl-8.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei63322\mpc\jfk.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei63322\mpc\msvcp144.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei63322\mpc\pcre2-8.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei63322\mpc\x.bat Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei63322\mpc\zlib-ng2.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei63322\msvcm90.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei63322\msvcp90.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei63322\msvcr90.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei63322\python27.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei63322\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei63322\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei65962\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei65962\bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei65962\data.exe.manifest Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei65962\microsoft.vc90.crt.manifest Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei65962\mpc\glib-2.0-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei65962\mpc\gmodule-2.0-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei65962\mpc\iconv-2.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei65962\mpc\intl-8.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei65962\mpc\jfk.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei65962\mpc\msvcp144.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei65962\mpc\pcre2-8.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei65962\mpc\x.bat Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei65962\mpc\zlib-ng2.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei65962\msvcm90.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei65962\msvcp90.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei65962\msvcr90.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei65962\python27.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei65962\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei65962\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei66802\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei66802\bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei66802\data.exe.manifest Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei66802\microsoft.vc90.crt.manifest Generic Write,Read Attributes

224 additional files are not displayed above.

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
Show More
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • UNKNOWN
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess

Shell Command Execution

c:\users\user\downloads\998f37be3f7dfa6439ad0573a34074355722ba90_0006738610 "c:\users\user\downloads\998f37be3f7dfa6439ad0573a34074355722ba90_0006738610"

Trending

Most Viewed

Loading...