Threat Database Stealers Trojan.PyStealer.A

Trojan.PyStealer.A

By CagedTech in Stealers, Trojans

Threat Scorecard

Popularity Rank: 6,128
Threat Level: 80 % (High)
Infected Computers: 2,736
First Seen: October 4, 2023
Last Seen: July 20, 2026
OS(es) Affected: Windows

The detection of Trojan.PyStealer.A on your system indicates a potential security threat that requires immediate attention. This report aims to provide you with a comprehensive understanding of the threat, its operational mechanisms, symptoms of infection, and most importantly, guidance on how to remove it from your system.

What Is Trojan.PyStealer.A?

Trojan.PyStealer.A, as detected by your security software, falls under the category of Trojan-type threats. Trojans are malicious programs that can allow unauthorized access to your computer, stealing sensitive information, or enabling other malicious activities. The name "Trojan.PyStealer.A" suggests it might be related to Python-based stealing malware, but without specific details, it's crucial to approach removal with a broad strategy that covers various potential impacts.

How Trojan.PyStealer.A Operates

Trojan-type threats like Trojan.PyStealer.A typically operate by disguising themselves as legitimate software. Once installed on your system, they can perform a variety of malicious actions. These can include data theft (such as login credentials, personal data, or financial information), installation of additional malware, or even allowing remote control of your computer. The exact mechanisms can vary widely, making it essential to take a comprehensive approach to removal and system cleaning.

Symptoms of Infection

Symptoms of a Trojan infection can be subtle and may not always be immediately apparent. Common indicators include unexpected changes to your system's performance, such as slower operation, frequent crashes, or the appearance of unwanted programs or toolbars in your browser. You might also notice unusual network activity, even when you're not using your computer. Since Trojans can masquerade as legitimate programs, vigilance and regular system checks are crucial for early detection.

How to Remove Trojan.PyStealer.A

  1. Boot into Safe Mode with Networking: This will limit the malware's ability to interfere with the removal process. Restart your computer and press the key to access your boot menu (usually F8, F12, or Del), then select Safe Mode with Networking.
  2. Perform a Full Scan with a Reputable Tool: Utilize a trusted anti-malware program, such as SpyHunter, to conduct a thorough scan of your system. Ensure your antivirus and anti-malware definitions are up-to-date before scanning.
  3. Uninstall Suspicious Programs: Go through your installed programs and remove any that you don't recognize or that were installed around the time your security software detected the Trojan.
  4. Reset Your Browsers: Trojans can often install malicious extensions or change browser settings. Resetting Chrome, Firefox, Edge, or any other browser you use can help remove these changes. You can usually find this option in the browser's settings or preferences area.
  5. Reboot and Re-scan: After completing the above steps, restart your computer in normal mode and perform another full scan with your anti-malware tool to ensure that no remnants of the Trojan remain on your system.

Conclusion

Removing Trojan.PyStealer.A from your system requires careful and thorough action to ensure all components of the malware are eliminated. By following the steps outlined above and maintaining vigilance in your computing practices, you can significantly reduce the risk of reinfection. Regularly updating your operating system, browsers, and security software, along with avoiding suspicious downloads and links, are key to protecting your digital security and privacy.

Analysis Report

General information

Family Name: Trojan.PyStealer.A
Signature status: No Signature

Known Samples

MD5: 18f423467df7e176e96fc96b59cd5633
SHA1: 48e41b2f34c2c09745ee11fa403021dafb37b4f2
File Size: 5.50 MB, 5499407 bytes
MD5: 12c3b9243f32c70ad2ecb85af2a86281
SHA1: 5e2a3377b34b35700396b846c8c9e9499b9c8704
File Size: 8.34 MB, 8336868 bytes
MD5: 9e1a4c964b5ad00994d1d1703b2f47b6
SHA1: 4241a27e72b0c35d2d0741db728307b653ac693f
File Size: 5.01 MB, 5008248 bytes
MD5: 6ef88815473d467f93caa5f9d90aab79
SHA1: fbd6dec3f90b52ea4210fa7e098568d9996920f8
File Size: 9.34 MB, 9339103 bytes
MD5: 3ff59ae65655f77a993c3e104d0d9a24
SHA1: 09fe3ae4e83a25a3f62e431a3733ba00e4e474a3
File Size: 1.76 MB, 1762354 bytes
Show More
MD5: fe8379e180afae37684e0b7212c19931
SHA1: 2567d88a06f00c240bb41f35f910c3de78a03a1f
File Size: 9.34 MB, 9335963 bytes
MD5: 86d39d069deb2c67784ca07250efb420
SHA1: 97fe441692d5c13edb0e61d6b90a8b9315433902
SHA256: 112EDF21EE22484A96F1FE6CF4A33B244FDF4F38E03F340854FC721D5A9CFBA2
File Size: 3.22 MB, 3217082 bytes
MD5: b47e7314b4d5f38c6cf3a19a755313fb
SHA1: 87f57d6805d62ae7c92872e97071ab51c46cd7c0
SHA256: A647544EBB49A90DCE6C697A69EDE549CC6A4A798F7F777DC93F00850C490F7B
File Size: 7.56 MB, 7557392 bytes
MD5: 90f5cc6815a943c90db6e2d0be996795
SHA1: 40367c01bf193ef011a091280b573d9cbe09ad17
SHA256: 7C8514FED4A341347E856E135FBFB157A306971B96B82B91691F519C8E8C6C2F
File Size: 9.20 MB, 9198542 bytes
MD5: b9928c2616d865227d5336c71ec3e1ba
SHA1: 73c1f87591ff42746e0713276d8b71b03044a050
SHA256: 7B93E39E90ACC845DA8055E274C98BA4B59D9C96FDF0C7059B676A3DB821914B
File Size: 8.04 MB, 8038138 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

File Traits

  • GetConsoleWindow
  • No Version Info
  • Py-installer
  • x64
  • zlib (In Overlay)
  • zlib overlay

Block Information

Total Blocks: 863
Potentially Malicious Blocks: 0
Whitelisted Blocks: 863
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 2 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
c:\users\user\appdata\local\temp\_mei10922\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10922\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10922\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10922\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10922\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10922\_ssl.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10922\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10922\bin\python39.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10922\bin\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10922\dlls\libcrypto-1_1.dll Generic Write,Read Attributes
Show More
c:\users\user\appdata\local\temp\_mei10922\dlls\libssl-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10922\pyexpat.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10922\python39.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10922\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10922\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10922\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11002\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11002\_ctypes.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11002\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11002\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11002\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11002\_multiprocessing.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11002\_queue.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11002\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11002\_ssl.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11002\api-ms-win-core-console-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11002\api-ms-win-core-datetime-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11002\api-ms-win-core-debug-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11002\api-ms-win-core-errorhandling-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11002\api-ms-win-core-fibers-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11002\api-ms-win-core-file-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11002\api-ms-win-core-file-l1-2-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11002\api-ms-win-core-file-l2-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11002\api-ms-win-core-handle-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11002\api-ms-win-core-heap-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11002\api-ms-win-core-interlocked-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11002\api-ms-win-core-libraryloader-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11002\api-ms-win-core-localization-l1-2-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11002\api-ms-win-core-memory-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11002\api-ms-win-core-namedpipe-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11002\api-ms-win-core-processenvironment-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11002\api-ms-win-core-processthreads-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11002\api-ms-win-core-processthreads-l1-1-1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11002\api-ms-win-core-profile-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11002\api-ms-win-core-rtlsupport-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11002\api-ms-win-core-string-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11002\api-ms-win-core-synch-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11002\api-ms-win-core-synch-l1-2-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11002\api-ms-win-core-sysinfo-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11002\api-ms-win-core-timezone-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11002\api-ms-win-core-util-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11002\api-ms-win-crt-conio-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11002\api-ms-win-crt-convert-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11002\api-ms-win-crt-environment-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11002\api-ms-win-crt-filesystem-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11002\api-ms-win-crt-heap-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11002\api-ms-win-crt-locale-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11002\api-ms-win-crt-math-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11002\api-ms-win-crt-process-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11002\api-ms-win-crt-runtime-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11002\api-ms-win-crt-stdio-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11002\api-ms-win-crt-string-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11002\api-ms-win-crt-time-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11002\api-ms-win-crt-utility-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11002\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11002\libcrypto-3.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11002\libffi-8.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11002\libssl-3.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11002\pyexpat.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11002\python311.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11002\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11002\ucrtbase.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11002\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei11002\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15522\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15522\_ctypes.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15522\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15522\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15522\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15522\_multiprocessing.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15522\_queue.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15522\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15522\_ssl.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15522\api-ms-win-core-console-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15522\api-ms-win-core-datetime-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15522\api-ms-win-core-debug-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15522\api-ms-win-core-errorhandling-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15522\api-ms-win-core-fibers-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15522\api-ms-win-core-file-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15522\api-ms-win-core-file-l1-2-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15522\api-ms-win-core-file-l2-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15522\api-ms-win-core-handle-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15522\api-ms-win-core-heap-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15522\api-ms-win-core-interlocked-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15522\api-ms-win-core-libraryloader-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15522\api-ms-win-core-localization-l1-2-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15522\api-ms-win-core-memory-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15522\api-ms-win-core-namedpipe-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15522\api-ms-win-core-processenvironment-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15522\api-ms-win-core-processthreads-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15522\api-ms-win-core-processthreads-l1-1-1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15522\api-ms-win-core-profile-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15522\api-ms-win-core-rtlsupport-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15522\api-ms-win-core-string-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15522\api-ms-win-core-synch-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15522\api-ms-win-core-synch-l1-2-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15522\api-ms-win-core-sysinfo-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15522\api-ms-win-core-timezone-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15522\api-ms-win-core-util-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15522\api-ms-win-crt-conio-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15522\api-ms-win-crt-convert-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15522\api-ms-win-crt-environment-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15522\api-ms-win-crt-filesystem-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15522\api-ms-win-crt-heap-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15522\api-ms-win-crt-locale-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15522\api-ms-win-crt-math-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15522\api-ms-win-crt-process-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15522\api-ms-win-crt-runtime-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15522\api-ms-win-crt-stdio-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15522\api-ms-win-crt-string-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15522\api-ms-win-crt-time-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15522\api-ms-win-crt-utility-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15522\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15522\libcrypto-3.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15522\libffi-8.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15522\libssl-3.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15522\pyexpat.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15522\python311.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15522\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15522\ucrtbase.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15522\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15522\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18002\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18002\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18002\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18002\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18002\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18002\_ssl.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18002\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18002\bin\python39.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18002\bin\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18002\dlls\libcrypto-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18002\dlls\libssl-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18002\pyexpat.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18002\python39.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18002\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18002\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18002\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei19202\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei19202\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei19202\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei19202\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei19202\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei19202\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei19202\libcrypto-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei19202\pyaudio\_portaudio.cp39-win_amd64.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei19202\python39.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei19202\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei19202\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei19202\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei19362\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei19362\_ctypes.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei19362\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei19362\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei19362\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei19362\_multiprocessing.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei19362\_queue.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei19362\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei19362\_ssl.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei19362\api-ms-win-core-console-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei19362\api-ms-win-core-datetime-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei19362\api-ms-win-core-debug-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei19362\api-ms-win-core-errorhandling-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei19362\api-ms-win-core-fibers-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei19362\api-ms-win-core-file-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei19362\api-ms-win-core-file-l1-2-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei19362\api-ms-win-core-file-l2-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei19362\api-ms-win-core-handle-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei19362\api-ms-win-core-heap-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei19362\api-ms-win-core-interlocked-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei19362\api-ms-win-core-libraryloader-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei19362\api-ms-win-core-localization-l1-2-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei19362\api-ms-win-core-memory-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei19362\api-ms-win-core-namedpipe-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei19362\api-ms-win-core-processenvironment-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei19362\api-ms-win-core-processthreads-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei19362\api-ms-win-core-processthreads-l1-1-1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei19362\api-ms-win-core-profile-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei19362\api-ms-win-core-rtlsupport-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei19362\api-ms-win-core-string-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei19362\api-ms-win-core-synch-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei19362\api-ms-win-core-synch-l1-2-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei19362\api-ms-win-core-sysinfo-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei19362\api-ms-win-core-timezone-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei19362\api-ms-win-core-util-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei19362\api-ms-win-crt-conio-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei19362\api-ms-win-crt-convert-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei19362\api-ms-win-crt-environment-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei19362\api-ms-win-crt-filesystem-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei19362\api-ms-win-crt-heap-l1-1-0.dll Generic Write,Read Attributes

1268 additional files are not displayed above.

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtFreeVirtualMemory
Show More
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetThreadState
Process Shell Execute
  • CreateProcess

Shell Command Execution

c:\users\user\downloads\48e41b2f34c2c09745ee11fa403021dafb37b4f2_0005499407.exe "c:\users\user\downloads\48e41b2f34c2c09745ee11fa403021dafb37b4f2_0005499407.exe"
c:\users\user\downloads\48e41b2f34c2c09745ee11fa403021dafb37b4f2_0005499407.exe "c:\users\user\downloads\48e41b2f34c2c09745ee11fa403021dafb37b4f2_0005499407.exe"
c:\users\user\downloads\48e41b2f34c2c09745ee11fa403021dafb37b4f2_0005499407.exe "c:\users\user\downloads\48e41b2f34c2c09745ee11fa403021dafb37b4f2_0005499407.exe"
c:\users\user\downloads\48e41b2f34c2c09745ee11fa403021dafb37b4f2_0005499407.exe "c:\users\user\downloads\48e41b2f34c2c09745ee11fa403021dafb37b4f2_0005499407.exe"
c:\users\user\downloads\48e41b2f34c2c09745ee11fa403021dafb37b4f2_0005499407.exe "c:\users\user\downloads\48e41b2f34c2c09745ee11fa403021dafb37b4f2_0005499407.exe"
Show More
c:\users\user\downloads\48e41b2f34c2c09745ee11fa403021dafb37b4f2_0005499407.exe "c:\users\user\downloads\48e41b2f34c2c09745ee11fa403021dafb37b4f2_0005499407.exe"
c:\users\user\downloads\48e41b2f34c2c09745ee11fa403021dafb37b4f2_0005499407.exe "c:\users\user\downloads\48e41b2f34c2c09745ee11fa403021dafb37b4f2_0005499407.exe"
c:\users\user\downloads\48e41b2f34c2c09745ee11fa403021dafb37b4f2_0005499407.exe "c:\users\user\downloads\48e41b2f34c2c09745ee11fa403021dafb37b4f2_0005499407.exe"
c:\users\user\downloads\48e41b2f34c2c09745ee11fa403021dafb37b4f2_0005499407.exe "c:\users\user\downloads\48e41b2f34c2c09745ee11fa403021dafb37b4f2_0005499407.exe"
c:\users\user\downloads\48e41b2f34c2c09745ee11fa403021dafb37b4f2_0005499407.exe "c:\users\user\downloads\48e41b2f34c2c09745ee11fa403021dafb37b4f2_0005499407.exe"
c:\users\user\downloads\48e41b2f34c2c09745ee11fa403021dafb37b4f2_0005499407.exe "c:\users\user\downloads\48e41b2f34c2c09745ee11fa403021dafb37b4f2_0005499407.exe"
c:\users\user\downloads\48e41b2f34c2c09745ee11fa403021dafb37b4f2_0005499407.exe "c:\users\user\downloads\48e41b2f34c2c09745ee11fa403021dafb37b4f2_0005499407.exe"
c:\users\user\downloads\48e41b2f34c2c09745ee11fa403021dafb37b4f2_0005499407.exe "c:\users\user\downloads\48e41b2f34c2c09745ee11fa403021dafb37b4f2_0005499407.exe"
c:\users\user\downloads\48e41b2f34c2c09745ee11fa403021dafb37b4f2_0005499407.exe "c:\users\user\downloads\48e41b2f34c2c09745ee11fa403021dafb37b4f2_0005499407.exe"
c:\users\user\downloads\48e41b2f34c2c09745ee11fa403021dafb37b4f2_0005499407.exe "c:\users\user\downloads\48e41b2f34c2c09745ee11fa403021dafb37b4f2_0005499407.exe"
c:\users\user\downloads\48e41b2f34c2c09745ee11fa403021dafb37b4f2_0005499407.exe "c:\users\user\downloads\48e41b2f34c2c09745ee11fa403021dafb37b4f2_0005499407.exe"
c:\users\user\downloads\48e41b2f34c2c09745ee11fa403021dafb37b4f2_0005499407.exe "c:\users\user\downloads\48e41b2f34c2c09745ee11fa403021dafb37b4f2_0005499407.exe"
c:\users\user\downloads\48e41b2f34c2c09745ee11fa403021dafb37b4f2_0005499407.exe "c:\users\user\downloads\48e41b2f34c2c09745ee11fa403021dafb37b4f2_0005499407.exe"
c:\users\user\downloads\48e41b2f34c2c09745ee11fa403021dafb37b4f2_0005499407.exe "c:\users\user\downloads\48e41b2f34c2c09745ee11fa403021dafb37b4f2_0005499407.exe"
c:\users\user\downloads\5e2a3377b34b35700396b846c8c9e9499b9c8704_0008336868.exe "c:\users\user\downloads\5e2a3377b34b35700396b846c8c9e9499b9c8704_0008336868.exe"
c:\users\user\downloads\fbd6dec3f90b52ea4210fa7e098568d9996920f8_0009339103.exe "c:\users\user\downloads\fbd6dec3f90b52ea4210fa7e098568d9996920f8_0009339103.exe"
c:\users\user\downloads\2567d88a06f00c240bb41f35f910c3de78a03a1f_0009335963.exe "c:\users\user\downloads\2567d88a06f00c240bb41f35f910c3de78a03a1f_0009335963.exe"
c:\users\user\downloads\87f57d6805d62ae7c92872e97071ab51c46cd7c0_0007557392 "c:\users\user\downloads\87f57d6805d62ae7c92872e97071ab51c46cd7c0_0007557392"
c:\users\user\downloads\73c1f87591ff42746e0713276d8b71b03044a050_0008038138 "c:\users\user\downloads\73c1f87591ff42746e0713276d8b71b03044a050_0008038138"

Related Posts

Trending

Most Viewed

Loading...