Threat Database Trojans Trojan.MSIL.Krypt.ZAJA

Trojan.MSIL.Krypt.ZAJA

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 11,405
Threat Level: 80 % (High)
Infected Computers: 106
First Seen: March 2, 2023
Last Seen: July 12, 2026
OS(es) Affected: Windows

The detection of Trojan.MSIL.Krypt.ZAJA on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to compromise the security and integrity of your computer, and it's essential to understand its nature and take steps to remove it.

What Is Trojan.MSIL.Krypt.ZAJA?

Trojan.MSIL.Krypt.ZAJA is a type of Trojan horse malware, which is a broad category of malicious software that disguises itself as legitimate programs. The name suggests that it may be related to encryption or cryptography, but without specific details, it's challenging to determine its exact purpose or behavior. Generally, Trojans are designed to allow unauthorized access to a computer system, steal sensitive information, or disrupt normal operations.

How Trojan.MSIL.Krypt.ZAJA Operates

Malware like Trojan.MSIL.Krypt.ZAJA typically operates by exploiting vulnerabilities in software or tricking users into installing it. Once inside a system, it can create backdoors for remote access, download additional malware, or capture sensitive data such as login credentials, credit card numbers, or personal information. The specific operations of Trojan.MSIL.Krypt.ZAJA are not detailed here, but it's crucial to recognize that its presence poses a significant risk to your digital security and privacy.

Symptoms of Infection

Identifying a Trojan infection can be challenging because these malicious programs often run in the background without obvious symptoms. However, some common signs of infection include slow system performance, frequent crashes, unusual pop-ups, or unfamiliar programs running on your computer. Additionally, you might notice changes in your browser settings, unexpected toolbars, or redirection to unwanted websites. If you suspect that your system is infected, it's vital to take immediate action to mitigate the damage.

How to Remove Trojan.MSIL.Krypt.ZAJA

  1. Boot your computer in Safe Mode with Networking to prevent the malware from loading and to allow for internet access. This will make it easier to download and install removal tools.
  2. Download and run a full scan with a reputable anti-malware tool, such as SpyHunter, to detect and remove all traces of the malware. Ensure the tool is updated with the latest definitions to improve detection rates.
  3. Uninstall any suspicious programs that you don't recognize or that were installed around the time the malware was detected. Be cautious and only remove programs you are sure are not essential to your system's operation.
  4. Reset your web browsers (Chrome, Firefox, Edge) to their default settings to remove any malicious extensions or settings changes made by the malware. This can often be done through the browser's settings or options menu.
  5. After completing the above steps, reboot your computer and run another full scan with your anti-malware tool to ensure that all components of the malware have been removed. This step is crucial to verify that your system is clean and secure.

Conclusion

Removing Trojan.MSIL.Krypt.ZAJA requires careful steps to ensure that all components of the malware are eliminated from your system. By following the removal guide and maintaining good digital hygiene practices, such as regularly updating your software, using strong antivirus protection, and being cautious with email attachments and downloads, you can significantly reduce the risk of future infections. Remember, vigilance and proactive measures are key to protecting your digital security and privacy in today's evolving cyber threat landscape.

Analysis Report

General information

Family Name: Trojan.MSIL.Krypt.ZAJA
Signature status: No Signature

Known Samples

MD5: 0a3316b8a73ebc603ec586093740b7bd
SHA1: a07c7fdb52a93d92bd9e43811d76aabe3533d17b
File Size: 810.50 KB, 810496 bytes
MD5: 3903ca99404fc73f7697e27956386836
SHA1: ee8a19d9c0fda9055f0e5bc0f209b01fd20bd9cb
SHA256: 3B621884E6193B1DD4596B3700468D147769AA2003ED419FF86207D0AB635A79
File Size: 679.94 KB, 679936 bytes
MD5: 379f16e1c880cf2bc5807f8298f58a6d
SHA1: df22613f9b711c534ba1fbbe0d9fbdea3a96bd25
SHA256: 5F57F3D280064517425EAF25AAA3E6B1D6DD057EA1A830C7C82CDE37C8E77EC2
File Size: 875.52 KB, 875520 bytes
MD5: 006a85af9bf423ce7c0e85c523c4cc35
SHA1: cc1ae24d7f9a1b55bdc0114f0f7b15a93f9b924e
SHA256: 4C954FD9E09342D22BBCAF40C7FA23CDC98E4C6700C5FE15B00AB20CE79A8C24
File Size: 1.18 MB, 1184768 bytes
MD5: 1836b99b62102ee42dea53f47f0f6eea
SHA1: e5ccaf9da793007b19ad13967a0c15d7a0d235bf
SHA256: 89B4A28E55EEF88FE477D7ECFE1049523C4A9CC0534553E577FD79D6864E370F
File Size: 1.00 MB, 1001472 bytes
Show More
MD5: d034d8aff401987b637a1988672c291f
SHA1: 1b135bd15d151bb2e2ca6fab71c9ecc8529f02ea
SHA256: E9ECA5B788051553A1ADBE6A250BAC27E9045D4EEF5BB90893C0AB2EAA9C7149
File Size: 1.08 MB, 1076736 bytes
MD5: 233182daec5e182b13b27ba597dd3fb9
SHA1: 143b4ba0a6b66b69e6473854d98437a26eb2c4e5
SHA256: 1FA61D10E1AE2D687B1EC435BE05AB7A49D57AA0B94F5D3D2313A92403AE0CF2
File Size: 3.12 MB, 3122688 bytes
MD5: 102c3db2ee3f341f96f553d3eeaee986
SHA1: 70c344f3e7987c873b4ff589eee192e8d7dca2b5
SHA256: 22088257D2B429FF7F7E4E2A86705C900FE5EF2658C881CB54B08C7BC99E7DA4
File Size: 978.43 KB, 978432 bytes
MD5: 71a9fbad07f65ad31aa81918176a2e70
SHA1: f6e36eadeed150a5df284b5c99abc602fdbfad43
SHA256: 8BDF926019B17F44617D964A7B52867BAAF2B59D2C28FD14AB64C2CA1A1C95B7
File Size: 3.13 MB, 3127808 bytes
MD5: e5abc56b84fa448b5265324d5685440d
SHA1: 1270610596afc676d960ea8c62dbfad49adf16fe
SHA256: 7D98BF329CA71558D32B6E0DC9E852955B0A8893D6E2618CFA75F63E2DE212DB
File Size: 885.76 KB, 885760 bytes
MD5: a00633eedb6ecab0531669a0e9ccfd9d
SHA1: 448280c7d5dc47dab83e6dbd5e85ff4efed03ab1
SHA256: 735B452EC15DE3F8BF2C5CFFB2102AF4BB6C76B9D0FF1A14104F85D11E8ECEA1
File Size: 1.12 MB, 1119744 bytes
MD5: d1e50f2f72660d2023a4c315ed55f783
SHA1: 012e80507ef8b289d0bb79a246957a4bcbe06370
SHA256: D649FB2C1260F70B0E752AFC6AEEDDA46B9DAE035B1188D1759573219F007210
File Size: 762.85 KB, 762848 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version
  • 1.2.0.0
  • 1.0.5718.16620
  • 1.0.5143.1477
  • 1.0.4283.17416
  • 1.0.2676.9016
  • 1.0.1243.23867
  • 1.0.497.675
  • 1.0.0.1142
  • 1.0.0.0
Comments Application to view remote cameras
Company Name
  • Lakhya's Innovation Inc.
  • Microsoft
  • Zanoza SDT
File Description
  • Ateceni
  • csjmd
  • fchyko
  • ihmpa
  • Lphug
  • Remote Cam Viewer
  • Rqoecqo
  • UpdateTelePlus
  • Vbbqirn
  • ZModeler3
Show More
  • zwxhnhr
File Version
  • 1.2.0.0
  • 1.0.7644.1716
  • 1.0.7127.27937
  • 1.0.6865.8168
  • 1.0.4035.20029
  • 1.0.3772.9410
  • 1.0.1089.9025
  • 1.0.0.1142
  • 1.0.0.0
Internal Name
  • Ateceni.exe
  • csjmd.exe
  • fchyko.exe
  • ihmpa.exe
  • Lphug.exe
  • Remote Cam Viewer.exe
  • Rqoecqo.exe
  • RvNULeu.exe
  • UpdateTelePlus.exe
  • Vbbqirn.exe
Show More
  • ZModeler3.exe
  • zwxhnhr.exe
Legal Copyright
  • Copyright © 2002-2016
  • Copyright © 2010
  • Copyright © 2011
  • Copyright © 2014
  • Copyright © 2019
  • Copyright © 2020
  • Copyright © 2021
  • Copyright © 2022
  • Copyright © 2025
  • Copyright © Lakhya's Innovation Inc. 2023
Show More
  • Copyright © Microsoft 2015
Legal Trademarks ljnath@ljnath.com
Original Filename
  • Ateceni.exe
  • csjmd.exe
  • fchyko.exe
  • ihmpa.exe
  • Lphug.exe
  • Remote Cam Viewer.exe
  • Rqoecqo.exe
  • RvNULeu.exe
  • UpdateTelePlus.exe
  • Vbbqirn.exe
Show More
  • ZModeler3.exe
  • zwxhnhr.exe
Product Name
  • Ateceni
  • csjmd
  • fchyko
  • ihmpa
  • Lphug
  • RemoteCamViewer
  • Rqoecqo
  • UpdateTelePlus
  • Vbbqirn
  • ZModeler
Show More
  • zwxhnhr
Product Version
  • 1.2.0.0
  • 1.0.7644.1716
  • 1.0.7127.27937
  • 1.0.6865.8168
  • 1.0.4035.20029
  • 1.0.3772.9410
  • 1.0.1089.9025
  • 1.0.0.1142
  • 1.0.0.0

Digital Signatures

Signer Root Status
{9EFF4844-491A-470D-ACDF-6DE67C29708C} {9EFF4844-491A-470D-ACDF-6DE67C29708C} Self Signed

File Traits

  • .NET
  • HighEntropy
  • NewLateBinding
  • RijndaelManaged
  • SmartAssembly
  • x86

Block Information

Total Blocks: 425
Potentially Malicious Blocks: 5
Whitelisted Blocks: 342
Unknown Blocks: 78

Visual Map

0 ? ? 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? ? 0 0 0 0 0 0 0 ? 0 0 ? 0 ? 0 0 ? 0 ? 0 ? 0 0 0 ? ? ? 0 0 ? 0 0 0 ? 0 0 0 0 0 ? 0 0 ? 0 0 0 0 0 ? ? x ? ? 0 ? 0 0 0 0 0 ? ? 0 0 0 0 0 ? ? ? 0 ? ? 0 0 ? 0 ? 0 0 0 ? 0 0 0 0 ? 0 0 ? 0 x ? 0 0 0 0 0 ? 0 0 ? 0 ? ? 0 0 0 ? 0 ? x ? 0 ? 0 0 0 0 ? ? ? 0 0 ? 0 0 ? 0 0 0 0 0 ? ? ? x ? ? ? 0 ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 ? ? ? 0 ? ? ? ? ? 0 ? x 0 ? 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Agent.VC
  • MSIL.Agent.VGC
  • MSIL.Injector.DWD
  • MSIL.Krypt.BADC
  • MSIL.Krypt.GBBT
Show More
  • MSIL.Krypt.VC
  • MSIL.Krypt.ZAJA
  • MSIL.Lockscreen.AN
  • MSIL.Njrat.H
  • MSIL.Small.FA
  • MSIL.Small.FC
  • MSIL.Stealer.YB
  • RobloxHack.D

Files Modified

File Attributes
\device\namedpipe\dav rpc service Generic Read,Write Data,Write Attributes,Write extended,Append data
\device\namedpipe\pshost.134099545259304411.5668.defaultappdomain.powershell Generic Read,Write Data,Write Attributes,Write extended,Append data,LEFT 524288
\device\namedpipe\pshost.134220064316570979.6448.defaultappdomain.powershell Generic Read,Write Data,Write Attributes,Write extended,Append data,LEFT 524288
\device\namedpipe\wkssvc Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.1.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.2.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\__psscriptpolicytest_0l0cjayl.box.ps1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_5disml5s.kej.psm1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_aa25r3lp.j0o.ps1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_ejzfkkxz.fij.psm1 Generic Write,Read Attributes
Show More
c:\users\user\appdata\local\temp\__psscriptpolicytest_gmoqcrwc.uqo.ps1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_hjryg0fm.i3a.ps1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_jm015j0b.cns.ps1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_nubtoms5.pkb.psm1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_xd3gqkpk.yky.psm1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_zgckqsau.t1i.psm1 Generic Write,Read Attributes
c:\users\user\downloads\zmodeler.exe Generic Write,Read Attributes
c:\users\user\downloads\zmodeler.exe Synchronize,Write Attributes

Registry Modifications

Key::Value Data API Name
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 搻䒴梁ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 坻濂櫓ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 瓞萮爅ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 蜿葁爅ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe り尐ꈉǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 忰ꈺǜ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing::enableconsoletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\installutil_rasapi32::enablefiletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\installutil_rasapi32::enableautofiletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\installutil_rasapi32::enableconsoletracing RegNtPreCreateKey
Show More
HKLM\software\wow6432node\microsoft\tracing\installutil_rasapi32::filetracingmask ￿ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\installutil_rasapi32::consoletracingmask ￿ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\installutil_rasapi32::maxfilesize  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\installutil_rasapi32::filedirectory %windir%\tracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\installutil_rasmancs::enablefiletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\installutil_rasmancs::enableautofiletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\installutil_rasmancs::enableconsoletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\installutil_rasmancs::filetracingmask ￿ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\installutil_rasmancs::consoletracingmask ￿ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\installutil_rasmancs::maxfilesize  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\installutil_rasmancs::filedirectory %windir%\tracing RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe �Z�o�� RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateMutant
Show More
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtDelayExecution
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenSymbolicLinkObject
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySymbolicLinkObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN
User Data Access
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserName
  • GetUserNameEx
  • GetUserObjectInformation
Encryption Used
  • BCryptOpenAlgorithmProvider
  • CryptAcquireContext
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
  • OutputDebugString
Process Manipulation Evasion
  • NtUnmapViewOfSection
  • ReadProcessMemory
  • VirtualAllocEx
Other Suspicious
  • AdjustTokenPrivileges
Process Terminate
  • TerminateProcess
Keyboard Access
  • GetKeyState
Process Shell Execute
  • CreateProcess

Shell Command Execution

"powershell" Start-Sleep -Seconds 5

Related Posts

Trending

Most Viewed

Loading...