Threat Database Trojans Trojan.Padodor.D

Trojan.Padodor.D

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 11,869
Threat Level: 80 % (High)
Infected Computers: 92
First Seen: November 12, 2021
Last Seen: May 27, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.Padodor.D
Signature status: No Signature

Known Samples

MD5: e7135bb5d4afdb8502921d8ecc669c95
SHA1: dc794d1d7da0be0dfd2bba45476ba9f481931e8e
SHA256: 02BF64B4A408B1DC291061E4405C24A0E8C66DEDA2C8C5FCD06210197E06306E
File Size: 95.77 KB, 95770 bytes
MD5: 00fc67b601912ac5109d24ee905be285
SHA1: 2695f7adad526d31e1e082c7f5fc8d02844b0242
SHA256: 2B6B767AC145176EDD317ABCC3B27875EFB754BF7C625DB6173E3925E48218CA
File Size: 67.07 KB, 67072 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have resources
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • 2+ executable sections
  • HighEntropy
  • No Version Info
  • x86

Block Information

Total Blocks: 1
Potentially Malicious Blocks: 1
Whitelisted Blocks: 0
Unknown Blocks: 0

Visual Map

x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Hangup.A
  • Hangup.AA
  • Hangup.AB
  • Hangup.AC
  • Hangup.AD
Show More
  • Hangup.AE
  • Padodor.CC
  • Padodor.D
  • Padodor.DA
  • Padodor.DB
  • Padodor.DC
  • Qukart.B

Files Modified

File Attributes
c:\windows\syswow64\abmmqkei.dll Generic Write,Read Attributes
c:\windows\syswow64\aohkhm32.dll Generic Write,Read Attributes
c:\windows\syswow64\aqhnkflf.dll Generic Write,Read Attributes
c:\windows\syswow64\bfjngalp.dll Generic Write,Read Attributes
c:\windows\syswow64\biibpjmp.dll Generic Write,Read Attributes
c:\windows\syswow64\bogeobnn.dll Generic Write,Read Attributes
c:\windows\syswow64\bqeola32.dll Generic Write,Read Attributes
c:\windows\syswow64\dfiaoefc.dll Generic Write,Read Attributes
c:\windows\syswow64\dkcild32.dll Generic Write,Read Attributes
c:\windows\syswow64\dmmjgdde.dll Generic Write,Read Attributes
Show More
c:\windows\syswow64\dncaic32.dll Generic Write,Read Attributes
c:\windows\syswow64\dnmmnn32.dll Generic Write,Read Attributes
c:\windows\syswow64\fdabdd32.dll Generic Write,Read Attributes
c:\windows\syswow64\fkccef32.dll Generic Write,Read Attributes
c:\windows\syswow64\fmmeml32.dll Generic Write,Read Attributes
c:\windows\syswow64\folepl32.dll Generic Write,Read Attributes
c:\windows\syswow64\gbbljm32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\gbbljm32.exe Generic Write,Read Attributes
c:\windows\syswow64\ggaahcbg.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\ggaahcbg.exe Generic Write,Read Attributes
c:\windows\syswow64\ggdnncqd.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\ggdnncqd.exe Generic Write,Read Attributes
c:\windows\syswow64\gqccpjmi.dll Generic Write,Read Attributes
c:\windows\syswow64\hbceajhp.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\hbceajhp.exe Generic Write,Read Attributes
c:\windows\syswow64\hbjknpbb.dll Generic Write,Read Attributes
c:\windows\syswow64\hgmdlb32.dll Generic Write,Read Attributes
c:\windows\syswow64\hhfnim32.dll Generic Write,Read Attributes
c:\windows\syswow64\hhgnei32.dll Generic Write,Read Attributes
c:\windows\syswow64\hijdfa32.dll Generic Write,Read Attributes
c:\windows\syswow64\hinpjk32.dll Generic Write,Read Attributes
c:\windows\syswow64\hjgcen32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\hjgcen32.exe Generic Write,Read Attributes
c:\windows\syswow64\hkbfdagk.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\hkbfdagk.exe Generic Write,Read Attributes
c:\windows\syswow64\hmoioc32.dll Generic Write,Read Attributes
c:\windows\syswow64\hnelkl32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\hnelkl32.exe Generic Write,Read Attributes
c:\windows\syswow64\hnepfmkm.dll Generic Write,Read Attributes
c:\windows\syswow64\hnjefknc.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\hnjefknc.exe Generic Write,Read Attributes
c:\windows\syswow64\ihfgmj32.dll Generic Write,Read Attributes
c:\windows\syswow64\ijepflob.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\ijepflob.exe Generic Write,Read Attributes
c:\windows\syswow64\ijgllk32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\ijgllk32.exe Generic Write,Read Attributes
c:\windows\syswow64\ijjiak32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\ijjiak32.exe Generic Write,Read Attributes
c:\windows\syswow64\ijpfkl32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\ijpfkl32.exe Generic Write,Read Attributes
c:\windows\syswow64\ilebdfib.dll Generic Write,Read Attributes
c:\windows\syswow64\innoak32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\innoak32.exe Generic Write,Read Attributes
c:\windows\syswow64\jaaqpela.dll Generic Write,Read Attributes
c:\windows\syswow64\jeckplja.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\jeckplja.exe Generic Write,Read Attributes
c:\windows\syswow64\jeoaem32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\jeoaem32.exe Generic Write,Read Attributes
c:\windows\syswow64\jhojgh32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\jhojgh32.exe Generic Write,Read Attributes
c:\windows\syswow64\jjlfgk32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\jjlfgk32.exe Generic Write,Read Attributes
c:\windows\syswow64\jjqobjee.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\jjqobjee.exe Generic Write,Read Attributes
c:\windows\syswow64\jkgkkj32.dll Generic Write,Read Attributes
c:\windows\syswow64\jlbhamje.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\jlbhamje.exe Generic Write,Read Attributes
c:\windows\syswow64\jlpllmlh.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\jlpllmlh.exe Generic Write,Read Attributes
c:\windows\syswow64\jnjomi32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\jnjomi32.exe Generic Write,Read Attributes
c:\windows\syswow64\kaaafljm.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\kaaafljm.exe Generic Write,Read Attributes
c:\windows\syswow64\kacnll32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\kacnll32.exe Generic Write,Read Attributes
c:\windows\syswow64\kbihop32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\kbihop32.exe Generic Write,Read Attributes
c:\windows\syswow64\kejqak32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\kejqak32.exe Generic Write,Read Attributes
c:\windows\syswow64\keland32.dll Generic Write,Read Attributes
c:\windows\syswow64\kfngpl32.dll Generic Write,Read Attributes
c:\windows\syswow64\kiobka32.dll Generic Write,Read Attributes
c:\windows\syswow64\kjheciom.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\kjheciom.exe Generic Write,Read Attributes
c:\windows\syswow64\kjjbhimk.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\kjjbhimk.exe Generic Write,Read Attributes
c:\windows\syswow64\kjlonh32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\kjlonh32.exe Generic Write,Read Attributes
c:\windows\syswow64\kjolch32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\kjolch32.exe Generic Write,Read Attributes
c:\windows\syswow64\klqhan32.dll Generic Write,Read Attributes
c:\windows\syswow64\ladclq32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\ladclq32.exe Generic Write,Read Attributes
c:\windows\syswow64\lahhgkce.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\lahhgkce.exe Generic Write,Read Attributes
c:\windows\syswow64\lamabj32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\lamabj32.exe Generic Write,Read Attributes
c:\windows\syswow64\lbadgo32.dll Generic Write,Read Attributes
c:\windows\syswow64\lbgdqn32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\lbgdqn32.exe Generic Write,Read Attributes
c:\windows\syswow64\lbmjed32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\lbmjed32.exe Generic Write,Read Attributes
c:\windows\syswow64\lbofkd32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\lbofkd32.exe Generic Write,Read Attributes
c:\windows\syswow64\leagaj32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\leagaj32.exe Generic Write,Read Attributes
c:\windows\syswow64\lekjhhff.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\lekjhhff.exe Generic Write,Read Attributes
c:\windows\syswow64\lganqe32.dll Generic Write,Read Attributes
c:\windows\syswow64\ljahihgb.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\ljahihgb.exe Generic Write,Read Attributes
c:\windows\syswow64\lkceogep.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\lkceogep.exe Generic Write,Read Attributes
c:\windows\syswow64\lmiqjbck.dll Generic Write,Read Attributes
c:\windows\syswow64\lqikeb32.dll Generic Write,Read Attributes
c:\windows\syswow64\maajmikj.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\maajmikj.exe Generic Write,Read Attributes
c:\windows\syswow64\magpap32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\magpap32.exe Generic Write,Read Attributes
c:\windows\syswow64\makimppm.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\makimppm.exe Generic Write,Read Attributes
c:\windows\syswow64\mdoodj32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\mdoodj32.exe Generic Write,Read Attributes
c:\windows\syswow64\meeigo32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\meeigo32.exe Generic Write,Read Attributes
c:\windows\syswow64\mfddbipi.dll Generic Write,Read Attributes
c:\windows\syswow64\mfhlpgbp.dll Generic Write,Read Attributes
c:\windows\syswow64\mhhnoieg.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\mhhnoieg.exe Generic Write,Read Attributes
c:\windows\syswow64\mhnooc32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\mhnooc32.exe Generic Write,Read Attributes
c:\windows\syswow64\mjcbee32.dll Generic Write,Read Attributes
c:\windows\syswow64\mkaefnlc.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\mkaefnlc.exe Generic Write,Read Attributes
c:\windows\syswow64\mkbfdl32.dll Generic Write,Read Attributes
c:\windows\syswow64\mlepno32.dll Generic Write,Read Attributes
c:\windows\syswow64\mllhea32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\mllhea32.exe Generic Write,Read Attributes
c:\windows\syswow64\mnlgke32.dll Generic Write,Read Attributes
c:\windows\syswow64\namjiham.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\namjiham.exe Generic Write,Read Attributes
c:\windows\syswow64\nbfolk32.dll Generic Write,Read Attributes
c:\windows\syswow64\ndalijih.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\ndalijih.exe Generic Write,Read Attributes
c:\windows\syswow64\ndchojgf.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\ndchojgf.exe Generic Write,Read Attributes
c:\windows\syswow64\nhcnkhki.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\nhcnkhki.exe Generic Write,Read Attributes
c:\windows\syswow64\nhiokagg.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\nhiokagg.exe Generic Write,Read Attributes
c:\windows\syswow64\nlmmeg32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\nlmmeg32.exe Generic Write,Read Attributes
c:\windows\syswow64\nlndahnj.dll Generic Write,Read Attributes
c:\windows\syswow64\nmnccd32.dll Generic Write,Read Attributes
c:\windows\syswow64\oabenc32.dll Generic Write,Read Attributes
c:\windows\syswow64\obnelmjg.dll Generic Write,Read Attributes
c:\windows\syswow64\ocqkmdnf.dll Generic Write,Read Attributes
c:\windows\syswow64\ohhgfg32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\ohhgfg32.exe Generic Write,Read Attributes
c:\windows\syswow64\oiqgmoam.dll Generic Write,Read Attributes
c:\windows\syswow64\olafqfap.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\olafqfap.exe Generic Write,Read Attributes
c:\windows\syswow64\omcoan32.dll Generic Write,Read Attributes
c:\windows\syswow64\pbecdo32.dll Generic Write,Read Attributes
c:\windows\syswow64\pfniejbd.dll Generic Write,Read Attributes
c:\windows\syswow64\pjjjnpeg.dll Generic Write,Read Attributes
c:\windows\syswow64\pmnmmf32.dll Generic Write,Read Attributes
c:\windows\syswow64\qdlmof32.dll Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Hhfnim32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FAA099-1BAE-816E-D711-115290CEE717} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Mfhlpgbp.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FAA099-1BAE-816E-D711-115290CEE717} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Folepl32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FAA099-1BAE-816E-D711-115290CEE717} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Dkcild32.dll RegNtPreCreateKey
Show More
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FAA099-1BAE-816E-D711-115290CEE717} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Lqikeb32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FAA099-1BAE-816E-D711-115290CEE717} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Lbadgo32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FAA099-1BAE-816E-D711-115290CEE717} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Mjcbee32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FAA099-1BAE-816E-D711-115290CEE717} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Hbjknpbb.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FAA099-1BAE-816E-D711-115290CEE717} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Fkccef32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FAA099-1BAE-816E-D711-115290CEE717} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Fmmeml32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FAA099-1BAE-816E-D711-115290CEE717} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Oiqgmoam.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FAA099-1BAE-816E-D711-115290CEE717} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Mnlgke32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FAA099-1BAE-816E-D711-115290CEE717} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Pfniejbd.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FAA099-1BAE-816E-D711-115290CEE717} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Kiobka32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FAA099-1BAE-816E-D711-115290CEE717} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Abmmqkei.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FAA099-1BAE-816E-D711-115290CEE717} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Klqhan32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FAA099-1BAE-816E-D711-115290CEE717} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Bqeola32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FAA099-1BAE-816E-D711-115290CEE717} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Nmnccd32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FAA099-1BAE-816E-D711-115290CEE717} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Nlndahnj.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FAA099-1BAE-816E-D711-115290CEE717} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Pbecdo32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FAA099-1BAE-816E-D711-115290CEE717} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Lganqe32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FAA099-1BAE-816E-D711-115290CEE717} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Dfiaoefc.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FAA099-1BAE-816E-D711-115290CEE717} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Pmnmmf32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FAA099-1BAE-816E-D711-115290CEE717} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Hinpjk32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FAA099-1BAE-816E-D711-115290CEE717} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Dmmjgdde.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FAA099-1BAE-816E-D711-115290CEE717} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Lmiqjbck.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FAA099-1BAE-816E-D711-115290CEE717} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Omcoan32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FAA099-1BAE-816E-D711-115290CEE717} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Pjjjnpeg.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FAA099-1BAE-816E-D711-115290CEE717} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Ihfgmj32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FAA099-1BAE-816E-D711-115290CEE717} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Hhgnei32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FAA099-1BAE-816E-D711-115290CEE717} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Hijdfa32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FAA099-1BAE-816E-D711-115290CEE717} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Mkbfdl32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FAA099-1BAE-816E-D711-115290CEE717} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Aqhnkflf.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FAA099-1BAE-816E-D711-115290CEE717} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Bogeobnn.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FAA099-1BAE-816E-D711-115290CEE717} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Nbfolk32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FAA099-1BAE-816E-D711-115290CEE717} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Biibpjmp.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FAA099-1BAE-816E-D711-115290CEE717} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Bfjngalp.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FAA099-1BAE-816E-D711-115290CEE717} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Dncaic32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FEACFF-FFCE-815E-A900-316290B5B738} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Dnmmnn32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Ilebdfib.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Mfddbipi.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Gqccpjmi.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Jaaqpela.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Oabenc32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Hmoioc32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Mlepno32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Jkgkkj32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Fdabdd32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Hnepfmkm.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Obnelmjg.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Ocqkmdnf.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Hgmdlb32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Keland32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Kfngpl32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Aohkhm32.dll RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 RegNtPreCreateKey

Windows API Usage

Category API
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • WinExec

Shell Command Execution

C:\WINDOWS\system32\Nhiokagg.exe
C:\WINDOWS\system32\Namjiham.exe
C:\WINDOWS\system32\Mkaefnlc.exe
C:\WINDOWS\system32\Mllhea32.exe
C:\WINDOWS\system32\Mhnooc32.exe
Show More
C:\WINDOWS\system32\Maajmikj.exe
C:\WINDOWS\system32\Lekjhhff.exe
C:\WINDOWS\system32\Lamabj32.exe
C:\WINDOWS\system32\Lbgdqn32.exe
C:\WINDOWS\system32\Lahhgkce.exe
C:\WINDOWS\system32\Leagaj32.exe
C:\WINDOWS\system32\Kacnll32.exe
C:\WINDOWS\system32\Kaaafljm.exe
C:\WINDOWS\system32\Kejqak32.exe
C:\WINDOWS\system32\Kbihop32.exe
C:\WINDOWS\system32\Jeckplja.exe
C:\WINDOWS\system32\Jhojgh32.exe
C:\WINDOWS\system32\Jeoaem32.exe

Trending

Most Viewed

Loading...