Threat Database Trojans Trojan.Kryptik.YKAG

Trojan.Kryptik.YKAG

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 13,696
Threat Level: 80 % (High)
Infected Computers: 118
First Seen: May 29, 2024
Last Seen: March 22, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.Kryptik.YKAG
Signature status: No Signature

Known Samples

MD5: 0641701c74849e113d1c2a0c2a264cdc
SHA1: 1181d06189751b1872d77d9c2ef93557a370cf61
SHA256: 3BF688AF8F907772FB8441CEAF6B3C0DD90E8E0AFA2E27138B9CAA0CAC6FA912
File Size: 2.31 MB, 2314240 bytes
MD5: 17296ab2df654c246919b2b485b2d604
SHA1: 998f37be3f7dfa6439ad0573a34074355722ba90
SHA256: CCABE86FB0BB73977478539D5311F51A6C64468D8CD54C74D7EC99956C010B69
File Size: 6.74 MB, 6738610 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version 1.0.0.0
Company Name Katiusha
File Description Katiusha
File Version 1.0.0.0
Internal Name Katiusha.dll
Original Filename Katiusha.dll
Product Name Katiusha
Product Version 1.0.0

File Traits

  • 2+ executable sections
  • dll
  • HighEntropy
  • VirtualAllocExNuma
  • x64

Block Information

Total Blocks: 709
Potentially Malicious Blocks: 0
Whitelisted Blocks: 709
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.DFCF
  • Agent.FGDS
  • AgentTesla.P
  • Filecoder.XI
  • Kryptik.YKAC
Show More
  • XLoader.A

Files Modified

File Attributes
c:\users\user\appdata\local\temp\_mei11962\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11962\bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11962\data.exe.manifest Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11962\microsoft.vc90.crt.manifest Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11962\mpc\glib-2.0-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11962\mpc\gmodule-2.0-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11962\mpc\iconv-2.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11962\mpc\intl-8.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11962\mpc\jfk.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11962\mpc\msvcp144.dll Generic Write,Read Attributes
Show More
c:\users\user\appdata\local\temp\_mei11962\mpc\pcre2-8.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11962\mpc\x.bat Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11962\mpc\zlib-ng2.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11962\msvcm90.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11962\msvcp90.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11962\msvcr90.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11962\python27.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11962\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11962\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei21962\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei21962\bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei21962\data.exe.manifest Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei21962\microsoft.vc90.crt.manifest Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei21962\mpc\glib-2.0-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei21962\mpc\gmodule-2.0-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei21962\mpc\iconv-2.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei21962\mpc\intl-8.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei21962\mpc\jfk.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei21962\mpc\msvcp144.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei21962\mpc\pcre2-8.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei21962\mpc\x.bat Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei21962\mpc\zlib-ng2.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei21962\msvcm90.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei21962\msvcp90.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei21962\msvcr90.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei21962\python27.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei21962\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei21962\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei25162\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei25162\bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei25162\data.exe.manifest Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei25162\microsoft.vc90.crt.manifest Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei25162\mpc\glib-2.0-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei25162\mpc\gmodule-2.0-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei25162\mpc\iconv-2.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei25162\mpc\intl-8.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei25162\mpc\jfk.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei25162\mpc\msvcp144.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei25162\mpc\pcre2-8.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei25162\mpc\x.bat Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei25162\mpc\zlib-ng2.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei25162\msvcm90.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei25162\msvcp90.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei25162\msvcr90.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei25162\python27.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei25162\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei25162\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei31482\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei31482\bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei31482\data.exe.manifest Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei31482\microsoft.vc90.crt.manifest Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei31482\mpc\glib-2.0-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei31482\mpc\gmodule-2.0-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei31482\mpc\iconv-2.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei31482\mpc\intl-8.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei31482\mpc\jfk.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei31482\mpc\msvcp144.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei31482\mpc\pcre2-8.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei31482\mpc\x.bat Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei31482\mpc\zlib-ng2.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei31482\msvcm90.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei31482\msvcp90.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei31482\msvcr90.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei31482\python27.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei31482\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei31482\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei36242\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei36242\bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei36242\data.exe.manifest Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei36242\microsoft.vc90.crt.manifest Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei36242\msvcm90.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei36242\msvcp90.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei42042\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei42042\bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei42042\data.exe.manifest Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei42042\microsoft.vc90.crt.manifest Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei42042\mpc\glib-2.0-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei42042\mpc\gmodule-2.0-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei42042\mpc\iconv-2.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei42042\mpc\intl-8.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei42042\mpc\jfk.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei42042\mpc\msvcp144.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei42042\mpc\pcre2-8.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei42042\mpc\x.bat Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei42042\mpc\zlib-ng2.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei42042\msvcm90.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei42042\msvcp90.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei42042\msvcr90.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei42042\python27.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei42042\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei42042\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei42162\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei42162\bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei42162\data.exe.manifest Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei42162\microsoft.vc90.crt.manifest Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei42162\mpc\glib-2.0-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei42162\mpc\gmodule-2.0-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei42162\mpc\iconv-2.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei42162\mpc\intl-8.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei42162\mpc\jfk.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei42162\mpc\msvcp144.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei42162\mpc\pcre2-8.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei42162\mpc\x.bat Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei42162\mpc\zlib-ng2.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei42162\msvcm90.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei42162\msvcp90.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei42162\msvcr90.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei42162\python27.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei42162\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei42162\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei47242\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei47242\bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei47242\data.exe.manifest Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei47242\microsoft.vc90.crt.manifest Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei47242\mpc\glib-2.0-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei47242\mpc\gmodule-2.0-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei47242\mpc\iconv-2.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei47242\mpc\intl-8.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei47242\mpc\jfk.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei47242\mpc\msvcp144.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei47242\mpc\pcre2-8.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei47242\mpc\x.bat Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei47242\mpc\zlib-ng2.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei47242\msvcm90.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei47242\msvcp90.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei47242\msvcr90.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei47242\python27.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei47242\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei47242\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei56082\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei56082\bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei56082\data.exe.manifest Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei56082\microsoft.vc90.crt.manifest Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei56082\mpc\glib-2.0-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei56082\mpc\gmodule-2.0-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei56082\mpc\iconv-2.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei56082\mpc\intl-8.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei56082\mpc\jfk.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei56082\mpc\msvcp144.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei56082\mpc\pcre2-8.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei56082\mpc\x.bat Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei56082\mpc\zlib-ng2.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei56082\msvcm90.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei56082\msvcp90.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei56082\msvcr90.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei56082\python27.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei56082\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei56082\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei63322\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei63322\bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei63322\data.exe.manifest Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei63322\microsoft.vc90.crt.manifest Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei63322\mpc\glib-2.0-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei63322\mpc\gmodule-2.0-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei63322\mpc\iconv-2.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei63322\mpc\intl-8.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei63322\mpc\jfk.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei63322\mpc\msvcp144.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei63322\mpc\pcre2-8.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei63322\mpc\x.bat Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei63322\mpc\zlib-ng2.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei63322\msvcm90.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei63322\msvcp90.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei63322\msvcr90.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei63322\python27.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei63322\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei63322\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei65962\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei65962\bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei65962\data.exe.manifest Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei65962\microsoft.vc90.crt.manifest Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei65962\mpc\glib-2.0-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei65962\mpc\gmodule-2.0-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei65962\mpc\iconv-2.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei65962\mpc\intl-8.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei65962\mpc\jfk.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei65962\mpc\msvcp144.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei65962\mpc\pcre2-8.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei65962\mpc\x.bat Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei65962\mpc\zlib-ng2.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei65962\msvcm90.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei65962\msvcp90.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei65962\msvcr90.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei65962\python27.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei65962\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei65962\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei66802\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei66802\bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei66802\data.exe.manifest Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei66802\microsoft.vc90.crt.manifest Generic Write,Read Attributes

224 additional files are not displayed above.

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
Show More
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • UNKNOWN
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess

Shell Command Execution

c:\users\user\downloads\998f37be3f7dfa6439ad0573a34074355722ba90_0006738610 "c:\users\user\downloads\998f37be3f7dfa6439ad0573a34074355722ba90_0006738610"

Trending

Most Viewed

Loading...