Threat Database Trojans Trojan.Filecoder.Python

Trojan.Filecoder.Python

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 13,072
Threat Level: 80 % (High)
Infected Computers: 542
First Seen: November 29, 2022
Last Seen: December 15, 2025
OS(es) Affected: Windows

SpyHunter Detects & Remove Trojan.Filecoder.Python

File System Details

Trojan.Filecoder.Python may create the following file(s):
# File Name MD5 Detections
1. 03437ecbf89f32b3c102297f094f1511f8da91ac54a23d2b076cbf8658f9d3ba.dll 960bd90211156c6140ce40430abd433d 4
2. 09a0caadc4df3d4278368f94f52007894c2b51d3785d985cb8e42646e8a33b68.dll d03848a6760af241d8641f65fbc2f166 4
3. 0accc0347c52f10382b328ab3f74795732f74d9a1636abcd65fc15087df17f71.dll 2becdd067c34f6ec0dd5045603d137d0 4
4. 120cad05c27ce8cb5a5f93559eed4321be6ddeccb4ea760fe77b7ac9792895cf.dll 86471e26ad535e780ed401bb0599310b 4
5. 2d6768d7a20d300a4768ab63b48be977a7faa9e77316bd9bed160ca47a61184a.dll 5576974fdce0117d7ebcaea79a6ff259 4
6. 2d95507aa1ea5d2a6313bc5c201cf76e6aae4c207aa0fafe8f1fcb03e94102ec.dll 25af3ae9f4ebe5413b0ca1080b69b0ca 4
7. 00d832b42a66653d59f642136c7d44d0baa37c05591a1773dfd45880f6e6e5f4.dll 6b894fc38b12c169489d89ef4233ecb0 2
8. 02760a34946e406cd3cad3e56945b0d3f5de324adccd0e95814f85ebb4d7b439.dll 2b9e3fb277d36944e3dab113feddfb3c 2
9. 0a809481eeb607b57343e7b67426c45e2197037024e4e9816e0f28d4ad14cbf9.dll 81eee7fab2fce566920be2a87ea4ee8f 2
10. 0c5c4d858efb8a897715ba623630ba5f528a9787d6cc456d24cf047dc5a62efa.dll ebad7d173423946dec34e04235c68387 2
11. 13f894c8a4cdae73f2d51b05a9d341569339f8da0b9839529f24c7304b48ce6a.dll 109dc1555f5e2e3401620fc3ddfcddb5 2
12. 1521df9c74d826651c61005617c7b5bce8347020456677a8c6818d4e49a666ab.dll 4d25bd8a92d770f7f75a25f816e224f8 2
13. 1539c5ab5c631df582727547d7fd4adabb66424c65bca9049e197833e5737fa6.dll e7a68b408277fd3740093d4621d508f5 2
14. 170fdb3925a301a3a84ee2e2ccc257fe2d5fa600cff92fe42a646b36347d1455.dll 0079a7f64624f620850c6e7c1124c91d 2
15. 17865bac17cbd75f131a9b66f31a9f249e95bd81df5e8ef8d45a26f2e7eb05da.dll 32efb76cb942ef1ca91c398239366563 2
16. 18957a53fd5db0e6ba655840cd091993e564aeff45fcaa02d7a10027a5c7d088.dll 1ab301da5ff25a1254ea98993fcd27ce 2
17. 1b3c69947e9391d95a427de4e3e7c13be6c06455549d16f21560b920d47e356e.dll 8243ea927a43c05393cf694bb836fb5e 2
18. 1fb1e8033692f29836cf73f89fec0fbac8ffb0e32d35cfaf037f16cb647f4106.dll ebe47fcf91371b9123dbf031d651672d 2
19. 2106ab01347d1d61ac9a54a34ea73915d69ea4315ea67c98ea5cba5510de1aba.dll 49e25b74d812d7d5170ff159df2acc2f 2
20. 2422d9a13a4dde705f8ecbe2333dbf4e37aa13ad7b1c90df2aa5111614975dfe.dll 898d24e81acfaf3c5e8a1154ffa0ad5e 2
21. 24af5a0d8d584acf8d583dcb6bbdcc16ed0e806c7caaa4fe7fdbd9c52c208c60.dll 018771edcc3bc4c6c76b307c20aa9ee9 2
22. 24b41ea15d82cb302b3ddff7a74bea2f7c60ee14fc5bba60e604615d06bff408.dll 674377c4665e616a57664e70ea7c5d69 2
23. 25c08ec4934816439866b05351ef62b9f8a6f4df49dc37b619ce8d7707088eec.dll 3eb0194ade891f972d35da4e26654314 2
24. 275fdcc4a303181ec3148b61fc1fdb355d93dd701b32bdc1aa3a5eab83000d4f.dll 2db7fa124bb890a799be0f76f68da27f 2
25. 281a1c1f4588d0e4501bab2b39c483c17f0029faf2c5962b01bf85d1fd80ae2c.dll 4e75de025fe6578cbe69fa96211635dc 2
26. 291ed001c2e996ba0f53b8633b959e5ed19fad33db3ed812d5b6e711cfb3e535.dll 4e5065ebf63e30e938a02b820a9919c1 2
27. 29a47d4681930521a35079ecb0f0dc36cdbb6d16652ba83e8b12561cbd40f661.dll d69235ee612e573c54a0a362dc9c435d 2
28. 2c4db1c97cc767c73d020e6f3671d867aa1f6cc2158a8c09b1d02e97babb90dd.dll bfd1f2ef110191ef1c977cdfc1a60452 2
29. 30f7fb15d5cbfa246e555db68cd3e21aa982e10158cbb08223e0d5e314f893ff.dll 2115f9bfd36e0c8bee27a4db2b7780ce 2
30. 18ed265d7f419a57ee6426260b92aef71e0f498a012afad9ba66ced6769d9953.dll 474e0552c7faa9f2140e872796931488 1
More files

Analysis Report

General information

Family Name: Trojan.Filecoder.Python
Signature status: No Signature

Known Samples

MD5: f960d33bc092c6ef99695ef7b1f85c43
SHA1: f6aba14531b50440058504940efdfa91c78d73e4
SHA256: E1EA8F6CB3F07586C4AADFA943B9D669011201DA2CB19DBBA922BE8223B4DFA9
File Size: 9.27 MB, 9270005 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Block Information

Total Blocks: 905
Potentially Malicious Blocks: 0
Whitelisted Blocks: 896
Unknown Blocks: 9

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? 0 ? ? 0 0 ? 0 0 0 0 ? ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 2 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
c:\users\user\appdata\local\temp\_mei18242\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\auto.tcl Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\clock.tcl Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\ascii.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\big5.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cns11643.enc Generic Write,Read Attributes
Show More
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp1250.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp1251.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp1252.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp1253.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp1254.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp1255.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp1256.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp1257.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp1258.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp437.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp737.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp775.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp850.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp852.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp855.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp857.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp860.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp861.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp862.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp863.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp864.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp865.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp866.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp869.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp874.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp932.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp936.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp949.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\cp950.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\dingbats.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\ebcdic.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\_tcl_data\encoding\euc-cn.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei18242\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\auto.tcl Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\clock.tcl Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\encoding\ascii.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\encoding\big5.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\encoding\cns11643.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\encoding\cp1250.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\encoding\cp1251.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\encoding\cp1252.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\encoding\cp1253.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\encoding\cp1254.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\encoding\cp1255.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\encoding\cp1256.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\encoding\cp1257.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\encoding\cp1258.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\encoding\cp437.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\encoding\cp737.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\encoding\cp775.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\encoding\cp850.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\encoding\cp852.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\encoding\cp855.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\encoding\cp857.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\encoding\cp860.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\encoding\cp861.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\encoding\cp862.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\encoding\cp863.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\encoding\cp864.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\encoding\cp865.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\encoding\cp866.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\encoding\cp869.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\encoding\cp874.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\encoding\cp932.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\encoding\cp936.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\encoding\cp949.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\encoding\cp950.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\encoding\dingbats.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\encoding\ebcdic.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\encoding\euc-cn.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\encoding\euc-jp.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\encoding\euc-kr.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\encoding\gb12345.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\encoding\gb1988.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\encoding\gb2312-raw.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\encoding\gb2312.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\encoding\iso2022-jp.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\encoding\iso2022-kr.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\encoding\iso2022.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\encoding\iso8859-1.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\encoding\iso8859-10.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\encoding\iso8859-11.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\encoding\iso8859-13.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\encoding\iso8859-14.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\encoding\iso8859-15.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\encoding\iso8859-16.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\encoding\iso8859-2.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\encoding\iso8859-3.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\encoding\iso8859-4.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\encoding\iso8859-5.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\encoding\iso8859-6.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\encoding\iso8859-7.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\encoding\iso8859-8.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\encoding\iso8859-9.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\encoding\jis0201.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\encoding\jis0208.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\encoding\jis0212.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\encoding\koi8-r.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\encoding\koi8-u.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\encoding\ksc5601.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\encoding\maccenteuro.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\encoding\maccroatian.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\encoding\maccyrillic.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\encoding\macdingbats.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\encoding\macgreek.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\encoding\maciceland.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\encoding\macjapan.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\encoding\macroman.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\encoding\macromania.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\encoding\macthai.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\encoding\macturkish.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\encoding\macukraine.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\encoding\shiftjis.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\encoding\symbol.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\encoding\tis-620.enc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\history.tcl Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\http1.0\http.tcl Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\http1.0\pkgindex.tcl Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\init.tcl Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\msgs\af.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\msgs\af_za.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\msgs\ar.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\msgs\ar_in.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\msgs\ar_jo.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\msgs\ar_lb.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\msgs\ar_sy.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\msgs\be.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\msgs\bg.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\msgs\bn.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\msgs\bn_in.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\msgs\ca.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\msgs\cs.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\msgs\da.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\msgs\de.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\msgs\de_at.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\msgs\de_be.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\msgs\el.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\msgs\en_au.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\msgs\en_be.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\msgs\en_bw.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\msgs\en_ca.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\msgs\en_gb.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\msgs\en_hk.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\msgs\en_ie.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\msgs\en_in.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\msgs\en_nz.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\msgs\en_ph.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\msgs\en_sg.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\msgs\en_za.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\msgs\en_zw.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\msgs\eo.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\msgs\es.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\msgs\es_ar.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\msgs\es_bo.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\msgs\es_cl.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\msgs\es_co.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\msgs\es_cr.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\msgs\es_do.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\msgs\es_ec.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\msgs\es_gt.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\msgs\es_hn.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\msgs\es_mx.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\msgs\es_ni.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\msgs\es_pa.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\msgs\es_pe.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\msgs\es_pr.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\msgs\es_py.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\msgs\es_sv.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\msgs\es_uy.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\msgs\es_ve.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\msgs\et.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\msgs\eu.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\msgs\eu_es.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\msgs\fa.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\msgs\fa_in.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\msgs\fa_ir.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\msgs\fi.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\msgs\fo.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\msgs\fo_fo.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\msgs\fr.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\msgs\fr_be.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\msgs\fr_ca.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\msgs\fr_ch.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\msgs\ga.msg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei79242\_tcl_data\msgs\ga_ie.msg Generic Write,Read Attributes

781 additional files are not displayed above.

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAddAtomEx
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
Show More
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWriteFile
  • UNKNOWN
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess

Shell Command Execution

c:\users\user\downloads\f6aba14531b50440058504940efdfa91c78d73e4_0009270005 "c:\users\user\downloads\f6aba14531b50440058504940efdfa91c78d73e4_0009270005"

Trending

Most Viewed

Loading...