PUP.Bulz.EA

The detection of PUP.Bulz.EA on your system indicates the presence of a potentially unwanted program (PUP) that may be causing issues with your computer's performance and security. It is essential to understand the nature of this threat and take appropriate steps to remove it and prevent future infections.

What Is PUP.Bulz.EA?

PUP.Bulz.EA is a type of malware that is classified as a potentially unwanted program. This category of threats includes software that may not be malicious in the classical sense but can still cause problems for users. PUPs often exhibit behaviors such as displaying unwanted advertisements, collecting user data without consent, or modifying system settings without permission. The presence of PUP.Bulz.EA suggests that your system has been compromised by such a program, which could lead to a range of issues, from annoying pop-ups to more serious security vulnerabilities.

How PUP.Bulz.EA Operates

PUPs like PUP.Bulz.EA typically operate by exploiting vulnerabilities in software or by tricking users into installing them. They may be bundled with other programs, or they might be downloaded from the internet through deceptive means. Once installed, PUP.Bulz.EA can start to exhibit its unwanted behaviors, which can range from displaying advertisements to more invasive activities like data collection or the installation of additional unwanted software. Understanding how PUP.Bulz.EA operates is crucial for developing an effective strategy to remove it and prevent similar infections in the future.

Symptoms of Infection

The symptoms of a PUP.Bulz.EA infection can vary but often include an increase in unwanted advertisements, unexpected changes to browser settings, the appearance of unfamiliar programs or toolbars, and overall system slowdown. Users may also notice that their browsing experience has become more intrusive, with pop-ups, redirects, or other forms of advertisement that were not present before. If you have noticed any of these symptoms, it is likely that your system is infected with PUP.Bulz.EA or a similar malware.

  • Increased appearance of unwanted advertisements
  • Changes to browser settings or homepage
  • Presence of unfamiliar programs or toolbars
  • System performance issues

How to Remove PUP.Bulz.EA

Removing PUP.Bulz.EA requires a systematic approach to ensure that all components of the malware are eliminated. Here are the steps to follow:

  1. Boot your computer in Safe Mode with Networking to prevent the malware from interfering with the removal process.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system. This will help identify and remove all files and registry entries associated with PUP.Bulz.EA.
  3. Uninstall any suspicious programs that were installed around the time the symptoms appeared. Be cautious and only remove programs that you are sure are not needed.
  4. Reset your web browsers (Chrome, Firefox, Edge) to their default settings to remove any unwanted changes made by the malware.
  5. Reboot your computer and perform another scan with your anti-malware tool to ensure that all remnants of PUP.Bulz.EA have been removed.

Conclusion

The removal of PUP.Bulz.EA is a critical step in restoring your system's security and performance. By following the steps outlined above and maintaining good computing practices, such as regularly updating your software and being cautious with downloads, you can protect your system from similar threats in the future. Remember, prevention and vigilance are key to keeping your computer safe from potentially unwanted programs and other forms of malware.

Analysis Report

General information

Family Name: PUP.Bulz.EA
Signature status: No Signature

Known Samples

MD5: 48a17958a04905f7b6906f644f23dd20
SHA1: dabbfee68acc6201bcf3a556293bee45559a94e3
SHA256: 44DEE38D6064A0F216EAE375F7237370F545A19F8D2DC9D28A64317940212A16
File Size: 5.01 MB, 5007645 bytes
MD5: 122e177d77ef5064c12431c82a7e0f9a
SHA1: 0761469718c5e4ba8f7c137fbced9a557ee37e74
SHA256: 04AED3CFB3824F161542647ED0B50FAFDE31BF23B4BC63EDCABDA259731E7E1C
File Size: 1.22 MB, 1217543 bytes
MD5: 3cba83a2a095227064c69283e3b1a7ec
SHA1: b8cbbb106e4f9f75baaa7ee304a28d4fa974cb84
SHA256: AF89046702800692A5694332C93A0D2D00CC03997EDD6523EFF111E8092417F5
File Size: 5.69 MB, 5688476 bytes
MD5: 7de9ef1409dfd34405c4fab5a056b3e0
SHA1: aa65355656c6f721803dc1be9e7c5fc6462a26e1
SHA256: 7FDAA2CF377042CAB81C02E3B1280EB2F26ED719EE9D900316EB6231AB4C2825
File Size: 7.31 MB, 7306092 bytes
MD5: bc172a6b9bfbf8ae6fdc81c3c465a338
SHA1: fabeaff0a9e77299c4bac1024d0a84a698d2ab09
SHA256: A030AF27E56386BBDF6B01E9D6B1AD7D371EC8689291A0A97222FEB13B5B81AB
File Size: 8.85 MB, 8853555 bytes
Show More
MD5: 2a51d449f9a6ea141876992c36f9f6f6
SHA1: 0dade6f37cfa2308bb663a43ab3fe4470a6d8687
SHA256: F8406FFF01529D39127336AB9132C74F427D554C7293B356CB6F363B86DC2BC3
File Size: 6.26 MB, 6256302 bytes
MD5: 41412d16cdc6f653e2781b58e06dba8e
SHA1: e3a6c10a8c56f1b7fa1d3da79f206211235f20db
SHA256: C6FA8803C361E3668A6D9725BF7989D357DBA306F81B8AEBC10A7F5284351A54
File Size: 4.57 MB, 4568362 bytes
MD5: 11f6eb5288162526a98c5d7a556b5b40
SHA1: e6aaedaab52684da836e428e5edafabd56ec45af
SHA256: 6C17DF97AA44266493241CB7027846545A24D4477638A245647CFE080D310889
File Size: 8.65 MB, 8646071 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

File Traits

  • GetConsoleWindow
  • No Version Info
  • Py-installer
  • x64
  • zlib (In Overlay)
  • zlib overlay

Block Information

Total Blocks: 862
Potentially Malicious Blocks: 2
Whitelisted Blocks: 860
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 2 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • CobaltStrike.XAA
  • Downloader.Agent.N

Files Modified

File Attributes
c:\users\user\appdata\local\temp\_mei10522\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10522\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10522\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10522\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10522\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10522\_wmi.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10522\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10522\libcrypto-3.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10522\python312.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10522\select.pyd Generic Write,Read Attributes
Show More
c:\users\user\appdata\local\temp\_mei10522\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10522\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei12082\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei12082\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei12082\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei12082\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei12082\_queue.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei12082\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei12082\_ssl.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei12082\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei12082\certifi\cacert.pem Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei12082\certifi\py.typed Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei12082\charset_normalizer\md.cp311-win_amd64.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei12082\charset_normalizer\md__mypyc.cp311-win_amd64.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei12082\libcrypto-3.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei12082\libssl-3.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei12082\python3.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei12082\python311.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei12082\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei12082\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei12082\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei12082\zstandard\_cffi.cp311-win_amd64.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei12082\zstandard\backend_c.cp311-win_amd64.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\api-ms-win-core-console-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\api-ms-win-core-datetime-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\api-ms-win-core-debug-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\api-ms-win-core-errorhandling-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\api-ms-win-core-file-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\api-ms-win-core-file-l1-2-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\api-ms-win-core-file-l2-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\api-ms-win-core-handle-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\api-ms-win-core-heap-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\api-ms-win-core-interlocked-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\api-ms-win-core-libraryloader-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\api-ms-win-core-localization-l1-2-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\api-ms-win-core-memory-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\api-ms-win-core-namedpipe-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\api-ms-win-core-processenvironment-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\api-ms-win-core-processthreads-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\api-ms-win-core-processthreads-l1-1-1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\api-ms-win-core-profile-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\api-ms-win-core-rtlsupport-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\api-ms-win-core-string-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\api-ms-win-core-synch-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\api-ms-win-core-synch-l1-2-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\api-ms-win-core-sysinfo-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\api-ms-win-core-timezone-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\api-ms-win-core-util-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\api-ms-win-crt-conio-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\api-ms-win-crt-convert-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\api-ms-win-crt-environment-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\api-ms-win-crt-filesystem-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\api-ms-win-crt-heap-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\api-ms-win-crt-locale-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\api-ms-win-crt-math-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\api-ms-win-crt-process-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\api-ms-win-crt-runtime-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\api-ms-win-crt-stdio-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\api-ms-win-crt-string-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\api-ms-win-crt-time-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\api-ms-win-crt-utility-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\libcrypto-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\python310.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\ucrtbase.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei15442\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17242\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17242\_ctypes.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17242\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17242\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17242\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17242\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17242\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17242\libcrypto-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17242\libffi-7.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17242\psutil\_psutil_windows.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17242\python3.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17242\python39.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17242\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17242\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17242\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17322\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17322\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei17322\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei22122\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei22122\_ctypes.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei22122\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei22122\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei22122\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei22122\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei22122\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei22122\libcrypto-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei22122\libffi-7.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei22122\psutil\_psutil_windows.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei22122\python3.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei22122\python39.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei22122\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei22122\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei22122\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei34602\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei34602\_ctypes.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei34602\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei34602\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei34602\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei34602\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei34602\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei34602\libcrypto-1_1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei34602\libffi-7.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei34602\psutil\_psutil_windows.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei34602\python3.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei34602\python39.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei34602\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei34602\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei34602\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei34682\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei34682\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei34682\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei34682\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei34682\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei34682\_wmi.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei34682\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei34682\libcrypto-3.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei34682\python312.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei34682\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei34682\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei34682\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35162\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35162\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35162\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35162\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35162\_queue.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35162\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35162\_ssl.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35162\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35162\certifi\cacert.pem Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35162\certifi\py.typed Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35162\charset_normalizer\md.cp311-win_amd64.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35162\charset_normalizer\md__mypyc.cp311-win_amd64.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35162\libcrypto-3.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35162\libssl-3.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35162\python3.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35162\python311.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35162\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35162\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35162\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35162\zstandard\_cffi.cp311-win_amd64.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35162\zstandard\backend_c.cp311-win_amd64.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35362\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35362\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35362\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35362\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35362\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35362\api-ms-win-core-console-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35362\api-ms-win-core-datetime-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35362\api-ms-win-core-debug-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35362\api-ms-win-core-errorhandling-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35362\api-ms-win-core-file-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35362\api-ms-win-core-file-l1-2-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35362\api-ms-win-core-file-l2-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35362\api-ms-win-core-handle-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35362\api-ms-win-core-heap-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35362\api-ms-win-core-interlocked-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35362\api-ms-win-core-libraryloader-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35362\api-ms-win-core-localization-l1-2-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35362\api-ms-win-core-memory-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35362\api-ms-win-core-namedpipe-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35362\api-ms-win-core-processenvironment-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35362\api-ms-win-core-processthreads-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35362\api-ms-win-core-processthreads-l1-1-1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35362\api-ms-win-core-profile-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35362\api-ms-win-core-rtlsupport-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35362\api-ms-win-core-string-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35362\api-ms-win-core-synch-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35362\api-ms-win-core-synch-l1-2-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35362\api-ms-win-core-sysinfo-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35362\api-ms-win-core-timezone-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35362\api-ms-win-core-util-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35362\api-ms-win-crt-conio-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35362\api-ms-win-crt-convert-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35362\api-ms-win-crt-environment-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35362\api-ms-win-crt-filesystem-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35362\api-ms-win-crt-heap-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei35362\api-ms-win-crt-locale-l1-1-0.dll Generic Write,Read Attributes

1841 additional files are not displayed above.

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
Show More
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWriteFile
  • UNKNOWN
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess

Shell Command Execution

c:\users\user\downloads\b8cbbb106e4f9f75baaa7ee304a28d4fa974cb84_0005688476 "c:\users\user\downloads\b8cbbb106e4f9f75baaa7ee304a28d4fa974cb84_0005688476"
c:\users\user\downloads\aa65355656c6f721803dc1be9e7c5fc6462a26e1_0007306092 "c:\users\user\downloads\aa65355656c6f721803dc1be9e7c5fc6462a26e1_0007306092"
c:\users\user\downloads\fabeaff0a9e77299c4bac1024d0a84a698d2ab09_0008853555 "c:\users\user\downloads\fabeaff0a9e77299c4bac1024d0a84a698d2ab09_0008853555"
c:\users\user\downloads\0dade6f37cfa2308bb663a43ab3fe4470a6d8687_0006256302 "c:\users\user\downloads\0dade6f37cfa2308bb663a43ab3fe4470a6d8687_0006256302"