Threat Database Trojans Trojan.Agent.KFC

Trojan.Agent.KFC

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 2,254
Threat Level: 80 % (High)
Infected Computers: 589
First Seen: March 13, 2024
Last Seen: July 10, 2026
OS(es) Affected: Windows

The detection of Trojan.Agent.KFC on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to compromise the security and integrity of your computer, potentially leading to unauthorized access, data theft, and other malicious activities. It is essential to understand the nature of this threat and take prompt action to remove it and prevent future infections.

What Is Trojan.Agent.KFC?

Trojan.Agent.KFC is a type of Trojan horse malware, which is a broad category of threats that disguise themselves as legitimate software or files to gain unauthorized access to a computer system. The name "Trojan.Agent.KFC" suggests that it is a variant of Trojan horse malware, but the specific characteristics and behaviors of this threat are not well-defined without additional context. Trojan horses are often used to deliver payloads such as spyware, adware, or other types of malware, which can compromise the security and performance of the infected system.

How Trojan.Agent.KFC Operates

Like other Trojan horses, Trojan.Agent.KFC is likely designed to operate stealthily, avoiding detection by security software and system administrators. It may use various techniques to evade detection, such as code obfuscation, anti-debugging, or exploiting vulnerabilities in software or operating systems. Once installed, the malware may establish communication with its command and control (C2) servers to receive instructions, upload stolen data, or download additional payloads. The exact mechanisms used by Trojan.Agent.KFC are unknown, but it is likely to follow a similar pattern of behavior as other Trojan horses.

Symptoms of Infection

The symptoms of a Trojan.Agent.KFC infection can vary depending on the specific payload and goals of the attackers. Common signs of infection include unusual system behavior, such as slow performance, crashes, or unexpected pop-ups. You may also notice suspicious network activity, such as unfamiliar connections or data transfers. In some cases, the malware may attempt to disguise itself as a legitimate program or system process, making it difficult to detect without specialized tools or expertise. If you suspect that your system is infected with Trojan.Agent.KFC, it is essential to take immediate action to contain and remove the threat.

How to Remove Trojan.Agent.KFC

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow for easier removal.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and detect any associated files or registry entries.
  3. Uninstall any suspicious programs or applications that may be related to the infection.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your system and perform a follow-up scan to ensure that the malware has been completely removed.

Conclusion

Removing Trojan.Agent.KFC from your system requires careful attention to detail and a thorough understanding of the threat. By following the steps outlined above and using reputable security tools, you can help to ensure the integrity and security of your system. It is also essential to take preventive measures to avoid future infections, such as keeping your operating system and software up to date, using strong antivirus protection, and being cautious when opening email attachments or downloading files from the internet. Remember that the detection of Trojan.Agent.KFC is a serious issue that requires prompt action to protect your system and data.

Analysis Report

General information

Family Name: Trojan.Agent.KFC
Signature status: No Signature

Known Samples

MD5: 2dde78794343872378fe4db8a516f34a
SHA1: 5cf919283a34e95a1ac22ffdad10eaa59c140937
SHA256: A4BD0BCEBB2C9BEA415A7D5262CEF5C0808DA3AE0B924A886347F28EBFA08506
File Size: 9.23 MB, 9230848 bytes
MD5: dd4cb9cc9c5e5bd16b201cb88d69cc10
SHA1: 59261e472fbca76e9bfbe17e5323ef5cc3c9e380
SHA256: 4C9F0ECEFDFD1A02884924EDBF7F580F2C659576801B8142AD88CE6AB6ABBD75
File Size: 4.31 MB, 4313088 bytes
MD5: e0e57b91e6d73c7447f4a7ebb6b316cd
SHA1: 3e8bde0a3565193e1cfb2cadbd4f22177837589a
SHA256: A617D16617A29BF5C70EBFC9F84DE91018C764461713969E54AF70A17EDCB196
File Size: 893.44 KB, 893440 bytes
MD5: 28b6353b9c623f96b06934319594af26
SHA1: de22bb393d08ca7de5ac13728191ad776ddbc8d4
SHA256: A03271A89F827DB9F73534B4ECFEC794B66E251F636DADCE942E00E59EF691F4
File Size: 3.91 MB, 3911680 bytes
MD5: 4770c870051f63c17db3561d9f1fc35c
SHA1: 00c5ebce8fd8f7d2aae5bd36a24f3e85217c8700
SHA256: DE32B5813F6F9539AFC031140A6CCC49E1665855E7851F562B755C28FC22671E
File Size: 492.03 KB, 492032 bytes
Show More
MD5: 61c121889598ae19263a87f902f07f25
SHA1: 7abce7aaecd94770a7e45b2ea9643f3301cc10d0
SHA256: 03FD2C6578DBA7E006FCF083D8C4800D5A1B90FE6D44E0A6FCF068FA532893B3
File Size: 5.05 MB, 5046784 bytes
MD5: 46e3fc947ea29027871ae9ef667dfa78
SHA1: 05f73620241c869512db95b045b056c710f60a49
SHA256: 0FF4CDAFDC1977C9133AE631540744DDF5642B34C6D19D5059C8546016A1F044
File Size: 3.09 MB, 3092480 bytes
MD5: ebc6b525b21a187f7496ee63e3bb2ce5
SHA1: 1f08cfc5c449e059916d4b0cfb7e3abd686d2203
SHA256: B2E2C8182C3F45C78D282225255B5E8104D45E6D2C9757307A143F640713FA23
File Size: 2.15 MB, 2145792 bytes
MD5: 4957b9c5994c37571025e4fa72c9bc87
SHA1: 0469cc3036ab34d99c60afedbd141e200547210b
SHA256: 68514AF9C9024DC8C07E0EE831534B3E020FC53C7509B3927A9384B2E7674916
File Size: 3.09 MB, 3092480 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is .NET application
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
Show More
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Assembly Version 1.0.0.0
Company Name Tsuda Kageyu
File Description
  • external_legit
  • MinHook - The Minimalistic API Hook Library for x64/x86
File Version
  • 1.3.3.0
  • 1.0.0.0
Internal Name
  • external_legit.exe
  • MinHookD
Legal Copyright
  • Copyright (C) 2009-2017 Tsuda Kageyu. All rights reserved.
  • Copyright © 2025
Legal Trademarks Tsuda Kageyu
Original Filename external_legit.exe
Product Name
  • external_legit
  • MinHook DLL
Product Version
  • 1.3.3.0
  • 1.0.0.0

File Traits

  • dll
  • imgui
  • x64

Block Information

Total Blocks: 3,780
Potentially Malicious Blocks: 440
Whitelisted Blocks: 1,998
Unknown Blocks: 1,342

Visual Map

0 0 0 0 ? 0 0 ? ? ? ? ? ? ? ? ? ? 0 0 ? ? x 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? 0 ? ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x x ? ? x 0 0 ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x 0 0 0 0 0 0 0 0 0 ? ? 0 ? 0 0 0 0 0 0 0 0 ? 0 ? ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 ? 0 0 0 0 ? ? ? ? 0 0 0 ? ? 0 0 ? ? 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 1 0 0 0 0 ? ? ? ? 0 x x ? 0 0 0 0 0 0 0 ? 0 0 1 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 x 0 0 0 0 0 x 0 0 0 0 0 0 1 0 ? 0 ? x 0 ? ? ? ? 0 ? ? x x ? 0 ? ? 0 0 ? ? x ? 0 x ? 0 ? ? 0 ? ? 0 ? ? ? ? ? 0 0 ? 0 ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? ? ? x x x x x x x x x x x x ? ? 0 ? ? ? ? ? x x x ? ? x x 0 x x x x ? ? x ? ? ? x 0 ? ? ? 0 ? ? x 1 0 ? x ? x ? ? ? x ? ? 0 x ? ? ? x ? ? ? x x x x ? ? ? x x ? 1 ? ? ? x 0 ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 x 0 ? ? x 0 0 ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? ? ? ? ? 0 ? ? ? ? ? 0 0 ? ? 0 ? ? ? ? ? ? 0 ? x ? ? x ? x ? 0 x ? ? ? x ? ? ? ? ? ? ? ? ? ? ? ? x ? ? ? ? x ? ? 0 ? 0 x x 0 ? 0 x x 0 ? 0 ? ? ? ? ? ? ? 0 ? ? x x ? ? ? 0 0 ? ? x 0 ? ? x x ? 0 0 0 x ? x ? x x 0 ? 0 ? ? 0 ? ? ? ? ? ? 0 ? ? ? x x x ? 0 ? x x x x ? 0 ? ? ? x ? 1 ? 1 ? ? x ? x ? ? ? ? 0 ? 0 ? ? ? ? 0 ? 0 x ? x ? ? ? ? 0 ? ? ? ? ? 0 ? ? ? ? x 0 x x ? ? ? ? ? x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 ? x x ? ? x ? ? ? ? ? 0 ? 0 ? ? ? ? 0 0 ? ? x ? x ? ? 0 ? ? ? ? 0 x x ? x x 0 x ? 0 ? ? x ? ? ? ? x ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? 0 ? 0 x ? x ? 0 ? ? ? ? x x 0 ? ? ? 0 ? ? ? ? ? x x ? x ? x ? ? ? 0 ? ? ? 0 0 ? ? ? x x x x x x x x x x x x x ? ? ? ? ? ? x ? x ? x x x ? x 0 x ? ? x ? 0 ? ? ? x ? ? ? ? ? 0 x ? ? 0 x ? 0 0 0 0 ? ? ? x x ? 0 x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 x ? ? ? 0 ? ? ? 0 0 ? x ? 0 x ? ? 0 ? ? ? 0 ? ? ? 0 ? ? ? 0 ? ? ? 0 ? ? 1 ? ? ? 1 ? ? ? 0 ? ? ? 0 ? ? ? 0 ? ? ? 0 ? ? ? 0 ? ? ? 0 x x ? 1 ? ? ? ? 0 ? ? ? 1 ? ? 0 ? ? ? ? x x ? ? ? 0 ? x 0 x x x x x 0 ? ? x ? 0 ? ? ? ? x ? 0 ? ? x ? 0 ? ? ? ? ? 0 ? ? 0 ? ? ? 0 ? 0 ? 0 ? 0 ? ? x ? 0 ? ? x ? 0 ? ? x ? 0 ? ? x ? 0 ? ? x ? 0 ? ? x ? 0 ? ? x ? 0 ? ? x ? 0 ? ? x ? 0 ? ? 0 ? ? ? ? ? ? ? ? ? 0 ? ? 0 ? ? 0 ? ? 0 ? ? 0 ? ? 0 ? x x ? x ? ? ? ? ? 1 x ? ? 0 ? x ? ? 0 x ? x ? ? 0 ? x ? ? ? ? 0 x ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 ? 0 0 0 ? 0 0 0 0 0 0 0 ? x ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x ? ? x x x ? x x x x ? ? x x x x ? ? x ? x ? ? ? ? x ? x x x x x x x ? x x x x ? x 0 ? x x x x ? x x x x x x x x x ? ? x x x x x x x x x x x x x x x x x x ? x 0 x x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 ? ? ? ? x ? ? x ? x x ? 0 ? ? ? ? ? x 0 x ? ? ? x x x ? ? x x 0 ? ? ? ? ? ? ? ? ? ? ? ? x ? x 0 0 0 0 0 0 0 x x x x ? 0 ? ? ? 0 ? ? ? ? 0 ? 0 ? ? ? 0 ? ? 0 0 ? ? ? ? ? x ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x 0 0 0 1 0 0 0 ? 0 x ? ? 0 0 0 0 0 ? 0 0 0 0 0 0 x x x x 0 x 0 ? ? x ? x x ? 1 0 ? 0 ? ? ? ? x ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? x 0 ? 0 x x 0 ? ? ? x x 0 0 ? ? ? ? x ? ? ? x 0 x x 0 ? ? ? 0 ? ? ? ? ? ? ? x ? x ? 0 ? ? ? ? ? ? ? x 0 ? ? 0 1 ? x x 0 ? x x 0 ? ? ? ? x 0 ? ? ? x 0 ? x ? ? 0 ? ? ? 0 ? ? 0 ? x ? 0 ? 0 ? ? ? 0 ? ? 0 ? ? 0 ? ? x ? ? 0 ? ? ? ? 0 ? ? ? ? 0 x x ? x ? x x ? 0 ? ? ? ? 0 ? 0 ? ? ? 0 ? ? ? ? x x x x x x x x x x x x x x x x x x x x x x x 0 x 0 x 0 x ? ? ? 0 ? ? 0 0 ? ? ? ? ? ? 0 ? x ? ? 0 ? x ? ? 0 ? 0 0 0 0 0 1 0 0 ? 0 0 0 ? ? x ? ? x x ? 0 ? ? ? ? ? 0 0 ? 0 ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? 0 ? ? x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 ? 0 ? 0 ? ? ? ? ? ? ? 0 ? ? 0 ? ? 0 ? ? 0 ? ? 0 ? ? 0 ? ? ? 0 0 ? ? ? 0 0 ? ? 0 x ? 0 ? x ? ? ? ? x ? 0 0 ? 0 ? ? ?
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
c:\users\user\downloads\le_config.json Generic Write,Read Attributes
c:\users\user\downloads\logs\log_17-12-2025.txt Generic Write,Read Attributes
c:\users\user\downloads\logs\log_19-11-2025.txt Generic Write,Read Attributes
c:\users\user\downloads\logs\log_28-12-2025.txt Generic Write,Read Attributes
c:\users\user\downloads\offset_cache.json Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe ▾㯚査ǜ RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 zi +�Bx#@�1HO@V�@��g��y�y�^�P������|��3������������`����� [�m��'��$�`�V��� RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 倔厒褟ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 痹཯킥ǜ RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcCreateSecurityContext
  • ntdll.dll!NtAlpcDeleteSecurityContext
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
Show More
  • ntdll.dll!NtCancelTimer2
  • ntdll.dll!NtCancelWaitCompletionPacket
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtCompareSigningLevels
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDelayExecution
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFlushProcessWriteBuffers
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtGetCachedSigningLevel
  • ntdll.dll!NtGetContextThread
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenMutant
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtQueryWnfStateNameInformation
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetSystemInformation
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtSuspendThread
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtTraceEvent
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtUnsubscribeWnfStateChange
  • ntdll.dll!NtUpdateWnfStateData
  • ntdll.dll!NtWaitForAlertByThreadId

55 additional items are not displayed above.

User Data Access
  • GetComputerName
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
Encryption Used
  • BCryptOpenAlgorithmProvider
Process Terminate
  • TerminateProcess

Trending

Most Viewed

Loading...