Threat Database Trojans Trojan.Qhost.F

Trojan.Qhost.F

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 2,932
Threat Level: 80 % (High)
Infected Computers: 12,486
First Seen: January 19, 2011
Last Seen: January 25, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.Qhost.F
Signature status: No Signature

Known Samples

MD5: 61f7a54d6ab535c5f8a3156376cbcbe2
SHA1: 8722c2771f7329ca15503faa2bd7e7b7be210864
SHA256: E448D9807765976C279E92E8C156D613207282C58C2E6E8A80F4711CBB238818
File Size: 6.00 MB, 6003719 bytes
MD5: eaac2678ae61addd9392575b28c02fb8
SHA1: 88b382e2098cb0d438efea6f886fbb1cac958390
SHA256: 32527E7A3614679ABAF2AAD92E7532679F574D469BFDA69E48AA8087134F80BB
File Size: 2.02 MB, 2021617 bytes
MD5: ac8368ff175dba0416e76274cdd19457
SHA1: ab27c8fb36d5afffe62438f08417b204a75dc316
SHA256: FC54770C7DBF6FDD28B3A6A5761E49F04A761F92017427125D5395CD14965A4C
File Size: 5.32 MB, 5321604 bytes
MD5: 36a9d27b4852dcffa8d3d67d7e1b2835
SHA1: 8b542deabd98fcc4e75dc102fe301ccb3c6b272c
SHA256: 14B85E74B7EFFE82C651AA6ED87493F835FD1D8E1FE4E7A4D943F3F3EDD9E4D9
File Size: 8.06 MB, 8060928 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

File Traits

  • big overlay
  • HighEntropy
  • No Version Info
  • Py-installer
  • x86
  • zlib (In Overlay)
  • zlib overlay

Block Information

Total Blocks: 830
Potentially Malicious Blocks: 0
Whitelisted Blocks: 830
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 2 0 2 0 0 1 0 0 0 0 0 0 0 0 1 0 0 0 0 1 0 0 0 0 2 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 2 0 0 0 0 0 0 0 0 0 0 2 0 0 0 2 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 2 0 0 1 0 1 1 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
c:\users\user\appdata\local\temp\_mei26362\_asyncio.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei26362\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei26362\_ctypes.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei26362\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei26362\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei26362\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei26362\_multiprocessing.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei26362\_overlapped.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei26362\_queue.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei26362\_socket.pyd Generic Write,Read Attributes
Show More
c:\users\user\appdata\local\temp\_mei26362\_ssl.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei26362\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei26362\libcrypto-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei26362\libffi-7.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei26362\libssl-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei26362\pyexpat.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei26362\python38.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei26362\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei26362\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei26362\url-creator.exe.manifest Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei26362\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35442\_asyncio.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35442\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35442\_ctypes.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35442\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35442\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35442\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35442\_multiprocessing.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35442\_overlapped.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35442\_queue.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35442\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35442\_ssl.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35442\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35442\libcrypto-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35442\libffi-7.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35442\libssl-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35442\pyexpat.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35442\python38.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35442\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35442\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35442\url-creator.exe.manifest Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35442\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei37522\_asyncio.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei37522\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei37522\_ctypes.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei37522\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei37522\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei37522\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei37522\_multiprocessing.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei37522\_overlapped.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei37522\_queue.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei37522\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei37522\_ssl.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei37522\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei37522\libcrypto-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei37522\libffi-7.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei37522\libssl-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei37522\pyexpat.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei37522\python38.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei37522\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei37522\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei37522\url-creator.exe.manifest Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei37522\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei65682\_asyncio.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei65682\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei65682\_ctypes.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei65682\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei65682\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei65682\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei65682\_multiprocessing.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei65682\_overlapped.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei65682\_queue.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei65682\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei65682\_ssl.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei65682\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei65682\libcrypto-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei65682\libffi-7.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei65682\libssl-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei65682\pyexpat.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei65682\python38.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei65682\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei65682\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei65682\url-creator.exe.manifest Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei65682\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei65842\_asyncio.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei65842\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei65842\_ctypes.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei65842\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei65842\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei65842\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei65842\_multiprocessing.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei65842\_overlapped.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei65842\_queue.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei65842\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei65842\_ssl.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei65842\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei65842\libcrypto-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei65842\libffi-7.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei65842\libssl-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei65842\pyexpat.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei65842\python38.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei65842\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei65842\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei65842\url-creator.exe.manifest Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei65842\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei66322\_asyncio.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei66322\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei66322\_ctypes.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei66322\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei66322\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei66322\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei66322\_multiprocessing.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei66322\_overlapped.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei66322\_queue.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei66322\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei66322\_ssl.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei66322\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei66322\libcrypto-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei66322\libffi-7.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei66322\libssl-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei66322\pyexpat.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei66322\python38.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei66322\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei66322\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei66322\url-creator.exe.manifest Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei66322\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei67722\_asyncio.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei67722\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei67722\_ctypes.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei67722\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei67722\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei67722\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei67722\_multiprocessing.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei67722\_overlapped.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei67722\_queue.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei67722\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei67722\_ssl.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei67722\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei67722\libcrypto-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei67722\libffi-7.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei67722\libssl-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei67722\pyexpat.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei67722\python38.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei67722\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei67722\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei67722\url-creator.exe.manifest Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei67722\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei68002\_asyncio.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei68002\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei68002\_ctypes.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei68002\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei68002\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei68002\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei68002\_multiprocessing.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei68002\_overlapped.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei68002\_queue.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei68002\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei68002\_ssl.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei68002\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei68002\libcrypto-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei68002\libffi-7.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei68002\libssl-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei68002\pyexpat.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei68002\python38.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei68002\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei68002\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei68002\url-creator.exe.manifest Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei68002\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei68322\_asyncio.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei68322\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei68322\_ctypes.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei68322\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei68322\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei68322\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei68322\_multiprocessing.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei68322\_overlapped.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei68322\_queue.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei68322\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei68322\_ssl.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei68322\libcrypto-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei68322\libffi-7.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei68322\libssl-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei68322\pyexpat.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei68322\python38.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei68322\url-creator.exe.manifest Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei68322\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei82\_asyncio.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei82\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei82\_ctypes.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei82\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei82\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei82\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei82\_multiprocessing.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei82\_overlapped.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei82\_queue.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei82\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei82\_ssl.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei82\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei82\libcrypto-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei82\libffi-7.dll Generic Write,Read Attributes

7 additional files are not displayed above.

Windows API Usage

Category API
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess

Shell Command Execution

c:\users\user\downloads\8722c2771f7329ca15503faa2bd7e7b7be210864_0006003719 "c:\users\user\downloads\8722c2771f7329ca15503faa2bd7e7b7be210864_0006003719"
c:\users\user\downloads\8722c2771f7329ca15503faa2bd7e7b7be210864_0006003719 "c:\users\user\downloads\8722c2771f7329ca15503faa2bd7e7b7be210864_0006003719"
c:\users\user\downloads\8722c2771f7329ca15503faa2bd7e7b7be210864_0006003719 "c:\users\user\downloads\8722c2771f7329ca15503faa2bd7e7b7be210864_0006003719"
c:\users\user\downloads\8722c2771f7329ca15503faa2bd7e7b7be210864_0006003719 "c:\users\user\downloads\8722c2771f7329ca15503faa2bd7e7b7be210864_0006003719"
c:\users\user\downloads\8722c2771f7329ca15503faa2bd7e7b7be210864_0006003719 "c:\users\user\downloads\8722c2771f7329ca15503faa2bd7e7b7be210864_0006003719"
Show More
c:\users\user\downloads\8722c2771f7329ca15503faa2bd7e7b7be210864_0006003719 "c:\users\user\downloads\8722c2771f7329ca15503faa2bd7e7b7be210864_0006003719"
c:\users\user\downloads\8722c2771f7329ca15503faa2bd7e7b7be210864_0006003719 "c:\users\user\downloads\8722c2771f7329ca15503faa2bd7e7b7be210864_0006003719"
c:\users\user\downloads\8722c2771f7329ca15503faa2bd7e7b7be210864_0006003719 "c:\users\user\downloads\8722c2771f7329ca15503faa2bd7e7b7be210864_0006003719"
c:\users\user\downloads\8722c2771f7329ca15503faa2bd7e7b7be210864_0006003719 "c:\users\user\downloads\8722c2771f7329ca15503faa2bd7e7b7be210864_0006003719"

Trending

Most Viewed

Loading...