Threat Database Trojans Trojan.Filecoder

Trojan.Filecoder

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 763
Threat Level: 90 % (High)
Infected Computers: 13,388
First Seen: December 25, 2012
Last Seen: January 13, 2026
OS(es) Affected: Windows

SpyHunter Detects & Remove Trojan.Filecoder

File System Details

Trojan.Filecoder may create the following file(s):
# File Name MD5 Detections
1. f8d907099731ba448fef98c4b100265ac37dc57ff26917ff3699fc0060f91cab.exe 9997853609388189c6aaec5511a1dd17 6
2. 909707bdd068bc153e9f225f20ce6b41264eddbc2e64752655c4eff470f0e956(1) 733003afba338698ccf49f4f23260b85 4
3. 1f15a3e297b9017c40276ad1c32d606c8beebbf432227b47360f3674bfb60127.bin ebad44d2a8c72765aa64bae691458a34 4
4. 7ce637575c601a6708c568b433cb36935d9c47559d69d3958f04687f398066b7.bin e2a216e07203ec64c98eed979f260edd 4
5. a.exe e6353f79779a553c822deab899649b1b 4
6. d60dc6965f6d68a3e7c82d42e90bfda7ad3c5874d2c59a66df6212aef027b455.exe 823e4c4e47e8dabe32fc700409a78537 3
7. ataware ransomware aa5348671cb56557925b185d4ebe875a 2
8. 1ad4c9e3d0e04e7f1e32e196ea1e87ed64237485baab4cfa4b07eed44d4b347d.bin 73a4cf1512fc097fc28b6b75915b34bf 2
9. cxmxjh.bin a14798d28ef66745b8e424b52abf0026 2
10. svchost.bin c6d90484c49c61234f01f8aa5c9de150 2
11. 366623b97142a54efd9be31c673c409bdcfbc6ca0bed50e9bbc9b73d7443a55b.bin 55c646dd6b45052eb4c779a476349003 2

Analysis Report

General information

Family Name: Trojan.Filecoder
Signature status: No Signature

Known Samples

MD5: 3c09c8d888f1f4d534f2c43d1b32595c
SHA1: c235f55faaac4f8f76d2e4fe63d9466ede928183
File Size: 813.04 KB, 813040 bytes
MD5: 5c914ee758fd3fd91541271a24bb6fbf
SHA1: e1a5e322ea82f545fa3ffdc5875a016b5f85b6e9
File Size: 666.62 KB, 666624 bytes
MD5: 281c8e120107d807fc03c824f0b5d768
SHA1: ae4bdaa9b2d02d55d92964119570c542aa4b2078
File Size: 8.81 MB, 8808553 bytes
MD5: c588e7ea938b7cbadea0638204e379f1
SHA1: 7354763b3202a96372fdd9a34b1a01b27fb8e196
SHA256: C24DF0B8329391E83B40AE1AEE843E1062FCB3985344899CFE72B1643A9914D7
File Size: 8.40 MB, 8400226 bytes
MD5: 19bf473e7cd2f872d1b06b2626cf8e8e
SHA1: 44d8b928dd23e6ccd670eeeafc5d360f565443b7
SHA256: 6C2B9452FC4DBD18CFE1631DBC7D36E8B8EFAA819948A82A34E5EA2A131FB979
File Size: 1.15 MB, 1147315 bytes
Show More
MD5: 7364d0eef2367ceabaed34a13410503f
SHA1: ff0faabc1b7da97720f789cbff5b9ef199033e74
SHA256: 84BDE248E4F4C504384BB3A3B9703E4EA7E033F9AA1160089FEC9C30AF6632D7
File Size: 314.88 KB, 314880 bytes
MD5: c88210dd31e4a12cc90677c3bb4ba516
SHA1: 07d0d52fab1305271bba6549cfb7527de69b86c9
SHA256: 41B4B2D1CD4565C49190B7C12B6BF495988E4F82F4E5B8499BF7D49B8A4E9D61
File Size: 6.11 MB, 6105203 bytes
MD5: d357dfaf47e5c69442d7216592425df1
SHA1: fabb0a4c27b2a0a5ea3d3516cd2c906f16d86ee4
SHA256: A0CC351767B38DBAB603CB095079EF0A536873C646840CAA471F62AA289D0E5B
File Size: 7.27 MB, 7271094 bytes
MD5: 51b4f3876b51263318d415f46250b921
SHA1: 3a58245bdf058159d22342aa0184a80bc667ca8e
SHA256: 3884CECC5A9ECC34298686109F9CD474E2DD93C2A3B634399FFC166F76B43301
File Size: 8.39 MB, 8385445 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has exports table
  • File is .NET application
  • File is 32-bit executable
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
Show More
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version
  • 4.0.0.0
  • 2.0.0.0
Comments Windows Management Agent
File Description
  • Povlsomware
  • Windows Management Agent
File Version
  • 2022.3.37.3410856
  • 4.0.0.0
  • 2.0.0.0
  • 1.00
Internal Name
  • Povlsomware.exe
  • TJprojMain
  • wpagnt.exe
Legal Copyright
  • (c) 2005-2024 Unity Technologies. All rights reserved.
  • Copyright © 2020
  • Copyright © EXO5
Original Filename
  • Povlsomware.exe
  • TJprojMain.exe
  • wpagnt.exe
Product Name
  • Povlsomware
  • Project1
  • Windows Management Agent
Product Version
  • 2022.3.37f1 (340ba89e4c23)
  • 4.0.0.0
  • 2.0.0.0
  • 1.00

Digital Signatures

Signer Root Status
EXO5 LLC SSL.com EV Code Signing Intermediate CA RSA R3 Self Signed

File Traits

  • .NET
  • Badsig autoit
  • HighEntropy
  • ntdll
  • RijndaelManaged
  • Run
  • WriteProcessMemory
  • x64
  • x86

Block Information

Total Blocks: 903
Potentially Malicious Blocks: 0
Whitelisted Blocks: 894
Unknown Blocks: 9

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? 0 ? ? 0 0 ? 0 0 0 0 ? ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 2 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.FSJ
  • CobaltStrike.XAA
  • Downloader.Agent.N
  • Farfli.DC
  • Injector.DSB
Show More
  • KillWin.H

Files Modified

File Attributes
c:\users\user\appdata\local\temp\_mei10122\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10122\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10122\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10122\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10122\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10122\_ssl.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10122\_zstd.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10122\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10122\libcrypto-3.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10122\libssl-3.dll Generic Write,Read Attributes
Show More
c:\users\user\appdata\local\temp\_mei10122\python314.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10122\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10122\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10122\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17122\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17122\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17122\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17122\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17122\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17122\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17122\libcrypto-3.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17122\python312.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17122\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\auto.tcl Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\clock.tcl Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\ascii.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\big5.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp1250.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp1251.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp1252.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp1253.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp1254.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp1255.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp1256.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp1257.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp1258.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp437.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp737.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp775.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp850.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp852.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp855.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp857.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp860.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp861.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp862.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp863.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp864.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp865.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp866.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp869.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp874.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp932.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp936.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp949.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp950.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\dingbats.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\ebcdic.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\euc-cn.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\euc-jp.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\euc-kr.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\gb12345.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\gb1988.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\gb2312-raw.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\gb2312.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\iso2022-jp.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\iso2022-kr.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\iso2022.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\iso8859-1.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\iso8859-10.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\iso8859-13.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\iso8859-14.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\iso8859-15.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\iso8859-16.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\iso8859-2.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\iso8859-3.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\iso8859-4.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\iso8859-5.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\iso8859-6.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\iso8859-7.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\iso8859-8.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\iso8859-9.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\jis0201.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\jis0208.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\jis0212.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\koi8-r.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\koi8-u.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\ksc5601.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\maccenteuro.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\maccroatian.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\maccyrillic.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\macdingbats.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\macgreek.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\maciceland.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\macjapan.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\macroman.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\macromania.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\macthai.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\macturkish.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\macukraine.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\shiftjis.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\symbol.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\tis-620.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\history.tcl Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\http1.0\http.tcl Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\http1.0\pkgindex.tcl Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\init.tcl Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\af.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\af_za.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\ar.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\ar_in.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\ar_jo.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\ar_lb.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\ar_sy.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\be.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\bg.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\bn.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\bn_in.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\ca.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\cs.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\da.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\de.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\de_at.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\de_be.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\el.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\en_au.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\en_be.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\en_bw.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\en_ca.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\en_gb.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\en_hk.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\en_ie.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\en_in.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\en_nz.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\en_ph.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\en_sg.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\en_za.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\en_zw.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\eo.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\es.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\es_ar.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\es_bo.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\es_cl.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\es_co.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\es_cr.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\es_do.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\es_ec.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\es_gt.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\es_hn.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\es_mx.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\es_ni.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\es_pa.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\es_pe.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\es_pr.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\es_py.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\es_sv.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\es_uy.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\es_ve.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\et.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\eu.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\eu_es.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\fa.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\fa_in.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\fa_ir.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\fi.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\fo.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\fo_fo.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\fr.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\fr_be.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\fr_ca.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\fr_ch.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\ga.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\ga_ie.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\gl.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\gl_es.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\gv.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\gv_gb.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\he.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\hi.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\hi_in.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\hr.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\hu.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\id.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\id_id.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\is.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\it.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\it_ch.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\ja.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\kl.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\kl_gl.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\ko.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\ko_kr.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\kok.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\kok_in.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\msgs\kw.msg Generic Write,Read Attributes

1494 additional files are not displayed above.

Windows API Usage

Category API
User Data Access
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Anti Debug
  • NtQuerySystemInformation
  • OutputDebugString
Service Control
  • StartServiceCtrlDispatcher
Syscall Use
  • ntdll.dll!NtAddAtomEx
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
Show More
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • UNKNOWN
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetMessage
  • win32u.dll!NtUserGetProp
  • win32u.dll!NtUserGetThreadState
  • win32u.dll!NtUserPeekMessage
  • win32u.dll!NtUserPostMessage
  • win32u.dll!NtUserShowWindow
Process Shell Execute
  • CreateProcess
Other Suspicious
  • SetWindowsHookEx
Process Manipulation Evasion
  • NtUnmapViewOfSection

Shell Command Execution

c:\users\user\downloads\7354763b3202a96372fdd9a34b1a01b27fb8e196_0008400226 "c:\users\user\downloads\7354763b3202a96372fdd9a34b1a01b27fb8e196_0008400226"
c:\users\user\downloads\fabb0a4c27b2a0a5ea3d3516cd2c906f16d86ee4_0007271094 "c:\users\user\downloads\fabb0a4c27b2a0a5ea3d3516cd2c906f16d86ee4_0007271094"
c:\users\user\downloads\3a58245bdf058159d22342aa0184a80bc667ca8e_0008385445 "c:\users\user\downloads\3a58245bdf058159d22342aa0184a80bc667ca8e_0008385445"

Related Posts

Trending

Most Viewed

Loading...