Threat Database Trojans Trojan.MSIL.Inject.ADF

Trojan.MSIL.Inject.ADF

By CagedTech in Trojans

Analysis Report

General information

Family Name: Trojan.MSIL.Inject.ADF
Signature status: No Signature

Known Samples

MD5: 40e43aae43b40f0b0445405bc4093191
SHA1: 80b479d1689d3a95ed22a6b96cd218026795704c
SHA256: 4D13A54240AED9900868F6D2ABE6D7CDF19882F2401919247A84394D8230F90F
File Size: 8.19 KB, 8192 bytes
MD5: 4b6e2d5115dfa828e70c4cdde5c017ff
SHA1: 7318b56c6b46f8977dd934b21cf3c9ffaff5efc3
SHA256: C6D6DEDB0FB19773CBBDE8E7F30C3A884A68844944CB665231D9ADFB1AD416EB
File Size: 8.19 KB, 8192 bytes
MD5: 014f23b9e234a2039303cded8b888b35
SHA1: 0722d1f2cec6a741390aed69b5b5cf9c2f3ec2b9
SHA256: 1827AF3EAC54F304A337168792FF856F844DAC2CB7F48AEC65189F99DA461FDA
File Size: 8.19 KB, 8192 bytes
MD5: 3ae93e5026bc08f511e069295306d2c5
SHA1: 79c405400bfe94f3e1db0208603ab58c3ee4e73f
SHA256: C2C60623C62660F66D8F5CC45C6AF5507FBB56309239E7D81FC75BDA16334C0C
File Size: 8.19 KB, 8192 bytes
MD5: 8584a27042225f2c8e10c0ca868dca35
SHA1: 11a383f423311b261d4615a67415e1a578d6e609
SHA256: A9646198BA3E53F7640B63320B5290D686F0F08A41B9A3EE6322C9BC3FBAA044
File Size: 8.19 KB, 8192 bytes
Show More
MD5: a3c70dc3351b8426246b837f23a703c3
SHA1: bed363d3131213186cc62b25e8dd2dd62b17c32e
SHA256: 200A6E80771F99CA6CE861770A49BCDD2096C0754EF13E560C862EFDBA246369
File Size: 8.19 KB, 8192 bytes
MD5: 826815bbe3fd50aae49215e3b747c98e
SHA1: c8ef6dd34346f0dacd869421688e4eff6cb98366
SHA256: DA7F9B213584F938E0C648B2639E14E2C4E17441B218F242E092C18C56466A65
File Size: 8.19 KB, 8192 bytes
MD5: b999fb500d0871cefe2af13320eed23f
SHA1: 42c78a8e1a61797e94094dd67183e8563c01cf38
SHA256: B1E8F41AD0A0BCBAE4F5FF1A6E08006A1EACBC6C2D72422B9D0EDB73AA734A71
File Size: 8.19 KB, 8192 bytes
MD5: 61ca220da41e392a5b32ce53e0a42663
SHA1: dae87545d9c098c8cda207736819b5b9eaa84886
SHA256: 406C77617B6A1E368F52A1DB6EE82888811B3F10104232E9864DA22A80B7515E
File Size: 8.19 KB, 8192 bytes
MD5: 3f52b73032370b276ef6c1b82ce57bb3
SHA1: c99b27d6357311340e62e510100a9396af0970ae
SHA256: C61956F6670CCBAD4ACE9E7101BACE29AA42BE66533E904A3AB361FA7A97DD13
File Size: 8.19 KB, 8192 bytes
MD5: d6f544467ffd47b0755ab24625d51ecd
SHA1: 6099d611bffb484608d139ad89391612d65dcf59
SHA256: 664CC5465B764CBBA3496D253BD98DAF2153157EBAF62C184EEE444317FFF937
File Size: 8.19 KB, 8192 bytes
MD5: b99d9b667cf8e86b171a48ab6f916f8f
SHA1: b5b05f95c74fbbf6a51c11cd9ebe70eb496c137a
SHA256: 2E9D45E10F07C5AF9F15FF75C301448E1E0B7CCFE22362D2E91A26ABA973EA30
File Size: 8.19 KB, 8192 bytes
MD5: 6d71a734367c8e89fd985bce3623f6a5
SHA1: add7203c532994110e4859f9bc35316792d7227f
SHA256: 0D0470BE2F2D3FDD93B77FED00A0501913951C2C8FB9D187BC3D610A59A7D2D4
File Size: 8.19 KB, 8192 bytes
MD5: b9775ec7bbdde35c5dfca60e1ab3cf23
SHA1: 14e1e1e7831fa5b3ecb992c1c98c572751c83764
SHA256: E828F370F017D915007141D9AAD0F81FF24CCAC222473AC202CA212CF31931D4
File Size: 8.19 KB, 8192 bytes
MD5: 2fb6c4fcbe799b162cf28ac685d31529
SHA1: 4314260367f4aa714a9ce21716368b7d3e3c3285
SHA256: 2B9B2711B877DF9341AEF0D02BA1D01F6D2A89C295069B67B21AD1FEDAE304E8
File Size: 8.19 KB, 8192 bytes
MD5: 9e39b291013d5650fbfd71022fc83a7f
SHA1: 961a2a8b4251599884ed8fcd06486bf468889bd5
SHA256: E3EDC1FC42573F91726243C4B4D27627370BDEA74737EBA5230D82AEAE393B7B
File Size: 8.19 KB, 8192 bytes
MD5: 8c4f770d218821de490f1aa8789f7a56
SHA1: 82a9373494703102387391306061a9d491178a92
SHA256: 72CB1EBF9D472263FDF3AC000D5609577454333E00564A4DCD3E7F3947B043DA
File Size: 8.19 KB, 8192 bytes
MD5: 3e53f7c62445e4e061e9c53819842cea
SHA1: 727ee32128243a1deb7c84b7e86854b7372b6bd2
SHA256: 8C241F3740154E2E472F4A8A0A8CBA628D3E115AF752764EE2E72E378891FE2E
File Size: 8.19 KB, 8192 bytes
MD5: b204791ed54f934263a130a22ee37ed1
SHA1: 6077feb592acefe8c2e70aed2c5015ec9bfeba5a
SHA256: 09B5895F810C274B82D2420EC094E5623FE53F55D119811BA2DDD8DF3F48B3FC
File Size: 8.19 KB, 8192 bytes
MD5: fa62651db9a6942e26b7511ecdc29b46
SHA1: 5c3bbb7cebfdfe4a672af83dca69330c767806a4
SHA256: EC2EEE94BCC306B9EBAD5C48AE6E61E63E8318141C74C05ACBCA2058BDBF7DA9
File Size: 8.19 KB, 8192 bytes
MD5: 88b7a4f077429313fd4156b9d4db42cf
SHA1: d7f775d6fde5166cda64d914b916a590769d36a5
SHA256: 91CF75934A5DBD1FC81E2ACBB4D60CE58484254EB0A162E0D4BD8E85A228DC31
File Size: 8.19 KB, 8192 bytes
MD5: 29d68825b7f280799166e1383eace149
SHA1: 0b152d9c3a4644db3a2d6e46721b42188dfd7ff7
SHA256: 7FD6B4EA294125499047013E549447F8A7A002A8FB3E9951A36786BD16DAE52B
File Size: 8.19 KB, 8192 bytes
MD5: a83f2b0abb8a9059613c9bf81931aaf0
SHA1: 7213d30a96800602315cceac984c47c9b9daad3b
SHA256: 68CF96A0468287FC22D24B979AA415A691F1F2AAE3F574402E630D19598C391C
File Size: 8.19 KB, 8192 bytes
MD5: dece8329412a7f248e10a3f04a3aad42
SHA1: 36d1296a76b35f97af9ae80580880de3fef35a46
SHA256: B1EDF2F8E9DE9AD6644A27205F41CEB08318B785AD7AF76F9CE9B144A59FAD9F
File Size: 8.19 KB, 8192 bytes
MD5: dd26169e7e8e0eca18d5378395559a18
SHA1: ad967a46db62cead89949fa3ee656e9fd45c85d7
SHA256: 341BF5A670E4BE8B4C153827721A75CEEFA6AFF6B84255B29B71D2094DF8D712
File Size: 8.19 KB, 8192 bytes
MD5: 18de1311ea797a6514f55b7d130779f2
SHA1: 15cc5b77813f12f0afa61ca364d9ed2d9a1e425d
SHA256: 84EC890404DABC43D8FE97E15172D67FAF07DAB87E21884E96331EF83B2C8B3B
File Size: 8.19 KB, 8192 bytes
MD5: e88557510ecf61db5883928fb1f2dd52
SHA1: e29c4accd071a0a6b9b5059f824f3987f37608f3
SHA256: 4CDEC3CB6F42C9AA4F694D1160310A4550973472DA71B828FABB1DC0C531C032
File Size: 8.19 KB, 8192 bytes
MD5: 8a80e8b0b13e8783309760c30b849e01
SHA1: 9c8aaf29f40f4cc04af9d8fd43641fbfa7d66a0e
SHA256: CD01BE8EBF269C0904B5B12576467B738C83E2F5DFA7B0B283517D089A9FEE71
File Size: 8.19 KB, 8192 bytes
MD5: 042e74b44ba62d20e4f83670219e852d
SHA1: a0d7b734ff63814dca78952c689a5c77d8ef950a
SHA256: 7DBA8E57C857D2EDDF4B9EE7C50030DF5F703C47DA8E43FB4D99E5B49BFCDFB6
File Size: 8.19 KB, 8192 bytes
MD5: d935196b714cb95ee7dae989b107e1fe
SHA1: e264017bc542d5c47a3f40e4b194902e36f613f3
SHA256: 12260ED4EAAB029FA3FCDE08A7C622E4841A310F42B26C4A00B12603C3870371
File Size: 8.19 KB, 8192 bytes
MD5: 19e3672c412d1b0ecfe76dbe64c2da2c
SHA1: 992d5f58511bd4613f9ff563006fc60fd610dcf2
SHA256: 19068F3B2FA1975BAE9A25D494E71B94D7A428768BF578408D39E710F145A9E1
File Size: 8.19 KB, 8192 bytes
MD5: 22582d6f527b9ba6d71364a57594cba6
SHA1: 513d7475b957fef8a3a18f79343abe34a8a99a40
SHA256: A49A106E284B1C773BECA5ABA6A8CB6D74A7A8B705719EEB0546BA8E646BCD56
File Size: 8.19 KB, 8192 bytes
MD5: a38e2a1c22ead072ad5375be7a006d42
SHA1: 70734f6d070156159e8ffecef270f0f54ef44672
SHA256: 3FA2366CB21ED588AB76DA746724AE2473E880EC198797C896A937312A8DC3F6
File Size: 8.19 KB, 8192 bytes
MD5: 03f1f296a33d91e1b44b7897ab980164
SHA1: 7010515324165b8b61737d46fd547252db87fcbd
SHA256: E187CF8E51AAB4C1B2EAD6C153A7785CCA9F9B6418F05741CFB3AB6849A2EB7C
File Size: 8.19 KB, 8192 bytes
MD5: 0beabff0a209ae20edda53b6eb9ed019
SHA1: 9bca064812b005f9d7788088a531fb220f205b9a
SHA256: 51099C15B2EE81D5E21EDAD1D2C6CEB5E557245C833696E2C425F310EB10BFD3
File Size: 8.19 KB, 8192 bytes
MD5: 7a2439ff11e4c9f538ac782d19a7c616
SHA1: e20208025eb43a97fc80c750622d3d6eaa6fdd88
SHA256: 50A20F69938102B96DE654941B231DDD64272F79D8EA808E1BE851ABA925E813
File Size: 8.19 KB, 8192 bytes
MD5: b01683be618925dd6651a3870d021e6e
SHA1: 127873a4865e06fae14a374548e2f0c1797a884b
SHA256: 27FDC7CF042BE063C3E7F6C8FA1568ADE0B7B6F170CF420416EEB3A7A920E9E1
File Size: 8.19 KB, 8192 bytes
MD5: 4ff749e1be6b4f757634a0cbf443dc5c
SHA1: cda9a4785382d3143735b797acbd62b6804eb156
SHA256: FE34855D49608972C8320A3FDBFCDC02F10E84699820D11BEAF139BFBE10E54D
File Size: 8.19 KB, 8192 bytes
MD5: 77427af89be84f203ce02fe83a366614
SHA1: 6a3092d1ef95df006643906b9179708d8276f0af
SHA256: 8745BE32B57A06E36A1401EFB20D2E7029CB004A71052751048A82C28D4DCF0F
File Size: 8.19 KB, 8192 bytes
MD5: 54a2b516dd619e9359dea3d58a11c8c2
SHA1: a0704ebffc2ff5b5dbd9487e177a7df120b1d112
SHA256: 77B84B62D643ABB928957A4FA795B23BC3DD76BE652CE43BD59C4E15B0F25A91
File Size: 8.19 KB, 8192 bytes
MD5: 890d8216bda29628b827962782420c26
SHA1: d42ef034eceb6c0112516f309a87053890957a1d
SHA256: C463967C7E9C69DC325FEFBE40DCD8A1F02D3527729CA91306DD38C6CF67C9D1
File Size: 8.19 KB, 8192 bytes
MD5: b9579044119c7e935c6c1e649d988b40
SHA1: cb65d9484c55b2df905865d34a1bbde76d77480e
SHA256: 20F2AF1B922DB995AE7E0E7470935493756E80BC87B10C964299C0FE28B3893E
File Size: 8.19 KB, 8192 bytes
MD5: 7a0277bdece70c49fa3eb9b3dff9df33
SHA1: 1f46811acf09169abc949eaa22e9348cab54666d
SHA256: 614C197E6D095DC3EC273541ADE878D0F367053F02A76628CA7CF93E8308131B
File Size: 8.19 KB, 8192 bytes
MD5: bab9d7361a9c15ee07b6adfa4889b481
SHA1: 3de444601ee9c1bbe968c5e710b4024ce9072b1e
SHA256: 3D660A1FEE80F29AFB5C6C25AE8D949224A8AAD9D47F5002B6A62646C917CF6C
File Size: 8.19 KB, 8192 bytes
MD5: 852c86cbfe7bc98fb0a32becafc48bee
SHA1: 4dab4881723b1af605af0a6710fafb1a8991688e
SHA256: DCDF4E74E33CB1C713F2B52DA6BE3FCE2FB71D317CBE73DF724BBFB73CE58B11
File Size: 8.19 KB, 8192 bytes
MD5: 94e278414b4323232a10aa536910abce
SHA1: 2533445ac87db6d04f93d4a6e4e356081e19ac0b
SHA256: F0C0EE0FDED48E7E14130637AC266B7880D587CDACC8602CDBD8F6AB09866451
File Size: 8.19 KB, 8192 bytes
MD5: b217aeccb34d4d6a135013230d5b2f60
SHA1: 370aeea58d0362d5c248507d3052657f05517dea
SHA256: 5A3897B073CCC54D0FEDBF09503624751300D4D39002C2DF437383AC48346F90
File Size: 8.19 KB, 8192 bytes
MD5: 00c80464cb1376a662bb6f061dbea01b
SHA1: abe48ee4d4a78a436ef0b1f2d36e1b8b6594d0e8
SHA256: 7B06A8034844418C8CD60EF99319989FEC93AC532057DD2C0A21BA00FE057AC4
File Size: 8.19 KB, 8192 bytes
MD5: f8e7665e24e5d3ae355201c04331bcbd
SHA1: 2e3260167db5fe9385df7380080800bf499f9e47
SHA256: BBB03311B02B54A48385758DDCC23F3A2C30F269AF41864189473549DACD298E
File Size: 8.19 KB, 8192 bytes
MD5: 00c8c9cb015c986f1a2206f46f25d8ef
SHA1: 72602772ba54b42e64bebdafc45da5da5795468a
SHA256: 1BE54AE11E45E97D80FE07C36DC01000FF4A18DF62E247BE531ECF0EE6AA24FA
File Size: 8.19 KB, 8192 bytes
MD5: c9253c7ff907fa145158a93fa06bf573
SHA1: 23a8b9061c8401b145b4c1c6358b1c8843d8cfd0
SHA256: 6E3D7E50A6CA4BD63D8918008B34E019B20B7566FA0AA0A03D390E6F10D5AB4D
File Size: 8.19 KB, 8192 bytes
MD5: 0d6a3f2b9e21768b46b6c888082aef15
SHA1: 1f26d5ec5f8bf63a5ff251daeec3cc7e7d0aaf34
SHA256: 06B0012F5B23A0D32BDACF46741EFFADA7AA8029E79D2AFCB05ABE37651A521F
File Size: 8.19 KB, 8192 bytes
MD5: 6d007a089a04f85ce140d44646a8c5d8
SHA1: 3c423df8c4452f5ae6bb70f5b51533f85c0b8cd3
SHA256: F5585AD17696C00EA408327CF0435D0FBC9E8B58316CC9944802B6F50300EDFA
File Size: 8.19 KB, 8192 bytes
MD5: fd4dd65fc681d1c129c4e0d132c541a8
SHA1: 22644aba06299059dbe5770878752d9a39d6c933
SHA256: 11316E2941BFEE45CC8CB4D53012B1544E23AEBB064A1298FAF8BFABDD4994B4
File Size: 8.19 KB, 8192 bytes
MD5: 1ab449e10e8282025af0217e47ad7299
SHA1: 7a61c2c149e6f5109f8fe43ae1bc8d6f772d7e62
SHA256: 2348A82EB620E8C206DEEEF7A88E42F2E75778726756FF017FBC7F3706FAF87C
File Size: 8.19 KB, 8192 bytes
MD5: f99598c7d21c16b5b78696e5d18e2a83
SHA1: e13bcaf54cc18e3dea87eae0f03de662c8e0c24d
SHA256: E2B38D3A76EB1E0FB9B41C72091C1B792834FB8540C01941B30673F0B91DF648
File Size: 8.19 KB, 8192 bytes
MD5: 1dbd4bdaa1d67d623978765200b419c3
SHA1: 41d036581432e0428d5b47190b642cc5d38de1cc
SHA256: 9DE0FCD244D95A887239BF5AE31BF3DFF864E325D867062ECC1EBF77918FDABE
File Size: 8.19 KB, 8192 bytes
MD5: 817a8e788a06dda6332e0671ce4e5c1a
SHA1: 7eabd9ba0bed9324ea57d21dcfa5980be00cc47a
SHA256: 7CED757A679C38DCD8730326FA922C71C8516A57CB40F2B98D390778CE462A71
File Size: 8.19 KB, 8192 bytes
MD5: c0c3815fe30e1267ad55de05fa9fb3fc
SHA1: 9cdf218f0864d061abff4f22774263a886eeecff
SHA256: 7AEDF7183357E6D7C96543FA13DFCF937207D8CD6AB6C721001548EC7161B9EC
File Size: 8.19 KB, 8192 bytes
MD5: 5314b021c46b2681e8fe89634bbe762f
SHA1: 0727d00f74a8ac24aae254de7c6aa687a4958da7
SHA256: BABB3C399E9DBB03221F9432882EB6A6CBE2E736414D559ACA87D1C08725B523
File Size: 8.19 KB, 8192 bytes
MD5: 2c2e58dd5d6b61a3b359139daf6f9616
SHA1: 28b188d1cd98951ab28e12e8308c78c8f065d31e
SHA256: 38760E67C5E7EA72DA51517E0EA1D60970D3CCCD5143AADD37A4B4C1BEECEFC6
File Size: 8.19 KB, 8192 bytes
MD5: d695da4c1018832d93d6a3d33518eebc
SHA1: 701daa2d463987e8d8dcd5ea681943d242e84fc7
SHA256: 64F0B4A8A8B70490EA92BDBDC525B2A6FA5AED9E1796FC4870D90C40C18F0ABD
File Size: 8.19 KB, 8192 bytes
MD5: 7ab9664e34a86d083c0c794442fe81ee
SHA1: 0b285a9e8ea34f41fe3e3de159efcf4955882845
SHA256: 91E6686B868B956771506221182DE1CB56571C485D2E313611990A3ABB596C79
File Size: 8.19 KB, 8192 bytes
MD5: 5d6d2eadc40093d5319f91e32ecc7235
SHA1: b40563b0f4fb7d5fc7cc8f220fc901ed0d5f5c76
SHA256: E58928EDACD73A136591DA55EAF162D34867B25596B2BCE3D8B1095BEA8758A0
File Size: 8.19 KB, 8192 bytes
MD5: 76c03c56f2fbc7f401670865bd03dc72
SHA1: f9d64d7feb5fdea659402342308231f10c634661
SHA256: 48517B45D7FF56E312B70FB8DEED41506E7C52DF7EED6DA033BFF78642E59904
File Size: 8.19 KB, 8192 bytes
MD5: 0fc953f6c3a704c8e49eb6fde0bc047c
SHA1: d0ef0e7d952397ffa621f08f69066e4e922add3f
SHA256: 5F7CF960FE17915A83AE204EC642B18E4FD7144ABE1629DA1B79F73DA1B1E825
File Size: 8.19 KB, 8192 bytes
MD5: e3787dad3dabdbc9563f75b1a42e8a67
SHA1: 4f869f83ca3b07dd2c5f4a0f16f03aa008950fde
SHA256: 12AE576E1696F7E74F31BE4569035231B095A2692BAC511EC7D223F06B7B3A02
File Size: 8.19 KB, 8192 bytes
MD5: 042aabd0d51ec6f7c9d492c0df38d7fb
SHA1: c1cb2d5c536e7151c6d9bea637e7aa243568d194
SHA256: 3E317347E3EDB35F329C6566610BEB1C661DFB04908CA803C22572B254AE8923
File Size: 8.19 KB, 8192 bytes
MD5: ad859bc86147742feb83421b03311a4e
SHA1: a2aa23a98e0c95257923df174577844e967c7af9
SHA256: 5B288038CF350D796462D59631FF8119D814EB300BD83FF872A9A46791014280
File Size: 8.19 KB, 8192 bytes
MD5: 8b7380de11d823d33d9e34db2267a94f
SHA1: 0dc009f114887dafa2f40fd4468bb515a8f54b5c
SHA256: D07B711F700FB713B2CE75FB0FD21FCC992FE4556341502D18FB6EA0840F5AE5
File Size: 8.19 KB, 8192 bytes
MD5: f68abeeb52dfbc847c07506ab892cd3b
SHA1: 71e21ae8a27744f060f6fd01a2c5b61d63917677
SHA256: CB161F1A0E552D7EDB88233011045CF3B70766C22CD3E9D4608D09F1F493EF21
File Size: 8.19 KB, 8192 bytes
MD5: 0cc9d831697c64f144f1eebaf6f2d43a
SHA1: 82055e8c5d07c0124a68fd0aaa2c88a939db1c09
SHA256: 4D6F534ABEA7E6810E74C2E500D2C826D194BA218F7F697D84169E23CEB2628A
File Size: 8.19 KB, 8192 bytes
MD5: 884ca9caa6fc4137c22760ba3a484dfa
SHA1: e798cb671c4ef596bf5bfde9aae543d58064a73c
SHA256: A90102F313F211396C7A34DA50D1A7DABB715306C9E8C66AC898565C5F4DB745
File Size: 8.19 KB, 8192 bytes
MD5: 5e70564892e1aab10fb2252afff0d5cc
SHA1: e5636b60f074827380f2d31a88fdb29796118c5e
SHA256: DBFF11F427DD22F6761DCD9DD67D75579304E2EBBF403FD6B538CF6B1958914D
File Size: 8.19 KB, 8192 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Assembly Version 0.0.0.0
File Version 0.0.0.0
Internal Name
  • Temp_0a12b7b0694b4805be0c378991bcfb88.dll
  • Temp_0d5a75628e4d465d9a97ac3bb6214a5b.dll
  • Temp_0dbe2139508747219a986bfefc6c5f9d.dll
  • Temp_0ff8eb1bcf224e5680213a835143fc96.dll
  • Temp_007b45ce5258458f961ed823bd4d7623.dll
  • Temp_03c768ccd433458296901960064844f0.dll
  • Temp_0436a9138d04477d9be2960d491c9b6d.dll
  • Temp_07f4ada3e0934fb39106dd586d9ddfb3.dll
  • Temp_0745aae153bb4f6d812ff7f59febfba0.dll
  • Temp_08da10f84bf044f6a9492d07d329ef39.dll
Show More
  • Temp_09b5aad3aa1b4186ab213937884bb4a7.dll
  • Temp_1b739095cb914ac4900b1291201354d0.dll
  • Temp_1d7423d8a455492e87d257540e138f95.dll
  • Temp_1dfa6c84d95b4d6485208a807d789877.dll
  • Temp_1e0c42dd54ea4538b726a8d49b463fab.dll
  • Temp_2a771edff1324db6a22e3c70d11f2280.dll
  • Temp_2cac3dea68424e6ba315ef8f02ecdbc8.dll
  • Temp_2d63c5685950417d96c9e7a4b9c907d8.dll
  • Temp_2f9451e0b9a94ec39993767c39cbec5a.dll
  • Temp_2fe3a155382a45db8f7df35a315ac8df.dll
  • Temp_3dcb74da2b7147cd86a5ff53c1ff9e11.dll
  • Temp_4a729c68055645f7892f74464f450f9f.dll
  • Temp_4cd96f8aa4c246dab32519a7050b5737.dll
  • Temp_4d12f7ec758c411e911528cae17dc73d.dll
  • Temp_6b74916b93964ee3a956b8589804f07b.dll
  • Temp_6c4b4f160088498eb16aad79fcd8ab58.dll
  • Temp_8d5da0b274514af7bc5e798bd7be9b09.dll
  • Temp_13f9a273e08c4e19a95c30a6f0dbaded.dll
  • Temp_20a6039d153544f3a9b789e1f0b49811.dll
  • Temp_21b956ebfdeb49519330bed50fbb62bd.dll
  • Temp_24e7a35ef5164a5f8ac14a0cc17465e0.dll
  • Temp_35d1dd1be9f94231afd06df5f60cbb80.dll
  • Temp_51a5aeca6244478a84fbc31a6d1ad8b2.dll
  • Temp_54f231665d9e4f3a9a87cd1d3b585b29.dll
  • Temp_59af28777c4a4700aa23349c8492be03.dll
  • Temp_63b075b970064e06b98d192f4c2f3fed.dll
  • Temp_74fbf25c417e41bc9f3fb523f0e76316.dll
  • Temp_91b4ba7e058a40779c54db74b0fdf75c.dll
  • Temp_94c074d4f5e749c79dcc9f3c19857ffe.dll
  • Temp_177ebc7089d6428ca31bae896ac2e4e0.dll
  • Temp_275fd73edd284e9286d83f5fe9de708a.dll
  • Temp_303f0b462d174f6ab6c33df2572d78d7.dll
  • Temp_477ddd9c668542848ee5b750bda83165.dll
  • Temp_480b9fb9bda54982bf87cf398cc64ead.dll
  • Temp_483d6214a3cb499598cedacac204fae2.dll
  • Temp_507a54f9ae0c4e54b78fb8ff90a87add.dll
  • Temp_712be2cc391248c0bb2ad45ad5d3e67e.dll
  • Temp_886de669fa094eb195d9884219cebaa3.dll
  • Temp_2970f9310f174e63a79c08c97c243efd.dll
  • Temp_6819dfcd85d24f33805cb7fbb9f52370.dll
  • Temp_8519ca473db844d5bdb52c054f1c0e01.dll
  • Temp_9484ad5ff46e423ca9ccd302c0510186.dll
  • Temp_22650d451f804f26bc8af5bf7735761d.dll
  • Temp_70752efa7ca04e5c972afa4a4b2bbd15.dll
  • Temp_444483f8bf9244f1a090309c53963fd8.dll
  • Temp_700097e685854ff0bc920712f4733f28.dll
  • Temp_4366897dcd464b85b4153524fd915560.dll
  • Temp_6658829feef9454da9287e578597ab24.dll
  • Temp_a04c404712394ac89646ff440b43f798.dll
  • Temp_a84dac3fb3c34f889c710e848aefe143.dll
  • Temp_a636493371d14c23aca5ee5f8c685b04.dll
  • Temp_b23840d25b5845f2a28cce236ec6766e.dll
  • Temp_bbe68ad8b71c4a55b4a94b9ce01e167f.dll
  • Temp_c92f8af4c55f428f8d022699d0f2af06.dll
  • Temp_c670bb3fd2d643d68deedbb3670a4e76.dll
  • Temp_cfdfcb44100244d0862bb575331a8708.dll
  • Temp_d75e0cae4431453491a0ed66708c7a95.dll
  • Temp_d3017c231b7541cb93cba988f6c35755.dll
  • Temp_da34b607a2ba4da0941a2a0858e5e677.dll
  • Temp_de7d41a571284b53a1ff1e7efa358f1d.dll
  • Temp_fc3ea88448bb455eb182844bbbebd92a.dll
  • Temp_ff0d2eca2ff1466c8aef1ab40bbff740.dll
  • Temp_ff108e1c24b74ebca9d9fdecab433662.dll
  • Temp_ff689e2590234c059aef62114b76b263.dll
Original Filename
  • Temp_0a12b7b0694b4805be0c378991bcfb88.dll
  • Temp_0d5a75628e4d465d9a97ac3bb6214a5b.dll
  • Temp_0dbe2139508747219a986bfefc6c5f9d.dll
  • Temp_0ff8eb1bcf224e5680213a835143fc96.dll
  • Temp_007b45ce5258458f961ed823bd4d7623.dll
  • Temp_03c768ccd433458296901960064844f0.dll
  • Temp_0436a9138d04477d9be2960d491c9b6d.dll
  • Temp_07f4ada3e0934fb39106dd586d9ddfb3.dll
  • Temp_0745aae153bb4f6d812ff7f59febfba0.dll
  • Temp_08da10f84bf044f6a9492d07d329ef39.dll
Show More
  • Temp_09b5aad3aa1b4186ab213937884bb4a7.dll
  • Temp_1b739095cb914ac4900b1291201354d0.dll
  • Temp_1d7423d8a455492e87d257540e138f95.dll
  • Temp_1dfa6c84d95b4d6485208a807d789877.dll
  • Temp_1e0c42dd54ea4538b726a8d49b463fab.dll
  • Temp_2a771edff1324db6a22e3c70d11f2280.dll
  • Temp_2cac3dea68424e6ba315ef8f02ecdbc8.dll
  • Temp_2d63c5685950417d96c9e7a4b9c907d8.dll
  • Temp_2f9451e0b9a94ec39993767c39cbec5a.dll
  • Temp_2fe3a155382a45db8f7df35a315ac8df.dll
  • Temp_3dcb74da2b7147cd86a5ff53c1ff9e11.dll
  • Temp_4a729c68055645f7892f74464f450f9f.dll
  • Temp_4cd96f8aa4c246dab32519a7050b5737.dll
  • Temp_4d12f7ec758c411e911528cae17dc73d.dll
  • Temp_6b74916b93964ee3a956b8589804f07b.dll
  • Temp_6c4b4f160088498eb16aad79fcd8ab58.dll
  • Temp_8d5da0b274514af7bc5e798bd7be9b09.dll
  • Temp_13f9a273e08c4e19a95c30a6f0dbaded.dll
  • Temp_20a6039d153544f3a9b789e1f0b49811.dll
  • Temp_21b956ebfdeb49519330bed50fbb62bd.dll
  • Temp_24e7a35ef5164a5f8ac14a0cc17465e0.dll
  • Temp_35d1dd1be9f94231afd06df5f60cbb80.dll
  • Temp_51a5aeca6244478a84fbc31a6d1ad8b2.dll
  • Temp_54f231665d9e4f3a9a87cd1d3b585b29.dll
  • Temp_59af28777c4a4700aa23349c8492be03.dll
  • Temp_63b075b970064e06b98d192f4c2f3fed.dll
  • Temp_74fbf25c417e41bc9f3fb523f0e76316.dll
  • Temp_91b4ba7e058a40779c54db74b0fdf75c.dll
  • Temp_94c074d4f5e749c79dcc9f3c19857ffe.dll
  • Temp_177ebc7089d6428ca31bae896ac2e4e0.dll
  • Temp_275fd73edd284e9286d83f5fe9de708a.dll
  • Temp_303f0b462d174f6ab6c33df2572d78d7.dll
  • Temp_477ddd9c668542848ee5b750bda83165.dll
  • Temp_480b9fb9bda54982bf87cf398cc64ead.dll
  • Temp_483d6214a3cb499598cedacac204fae2.dll
  • Temp_507a54f9ae0c4e54b78fb8ff90a87add.dll
  • Temp_712be2cc391248c0bb2ad45ad5d3e67e.dll
  • Temp_886de669fa094eb195d9884219cebaa3.dll
  • Temp_2970f9310f174e63a79c08c97c243efd.dll
  • Temp_6819dfcd85d24f33805cb7fbb9f52370.dll
  • Temp_8519ca473db844d5bdb52c054f1c0e01.dll
  • Temp_9484ad5ff46e423ca9ccd302c0510186.dll
  • Temp_22650d451f804f26bc8af5bf7735761d.dll
  • Temp_70752efa7ca04e5c972afa4a4b2bbd15.dll
  • Temp_444483f8bf9244f1a090309c53963fd8.dll
  • Temp_700097e685854ff0bc920712f4733f28.dll
  • Temp_4366897dcd464b85b4153524fd915560.dll
  • Temp_6658829feef9454da9287e578597ab24.dll
  • Temp_a04c404712394ac89646ff440b43f798.dll
  • Temp_a84dac3fb3c34f889c710e848aefe143.dll
  • Temp_a636493371d14c23aca5ee5f8c685b04.dll
  • Temp_b23840d25b5845f2a28cce236ec6766e.dll
  • Temp_bbe68ad8b71c4a55b4a94b9ce01e167f.dll
  • Temp_c92f8af4c55f428f8d022699d0f2af06.dll
  • Temp_c670bb3fd2d643d68deedbb3670a4e76.dll
  • Temp_cfdfcb44100244d0862bb575331a8708.dll
  • Temp_d75e0cae4431453491a0ed66708c7a95.dll
  • Temp_d3017c231b7541cb93cba988f6c35755.dll
  • Temp_da34b607a2ba4da0941a2a0858e5e677.dll
  • Temp_de7d41a571284b53a1ff1e7efa358f1d.dll
  • Temp_fc3ea88448bb455eb182844bbbebd92a.dll
  • Temp_ff0d2eca2ff1466c8aef1ab40bbff740.dll
  • Temp_ff108e1c24b74ebca9d9fdecab433662.dll
  • Temp_ff689e2590234c059aef62114b76b263.dll
Product Version 0.0.0.0

File Traits

  • .NET
  • dll
  • WriteProcessMemory
  • x86

Block Information

Total Blocks: 8
Potentially Malicious Blocks: 8
Whitelisted Blocks: 0
Unknown Blocks: 0

Visual Map

x x x x x x x x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Inject.ADF
  • MSIL.Inject.ED

Registry Modifications

Key::Value Data API Name
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtFreeVirtualMemory
Show More
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • UNKNOWN

Trending

Most Viewed

Loading...