Threat Database Stealers Trojan.Stealer.CP

Trojan.Stealer.CP

By CagedTech in Stealers, Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 47
First Seen: July 14, 2023
Last Seen: February 11, 2026
OS(es) Affected: Windows

The detection of Trojan.Stealer.CP on your system indicates a potential security threat that requires immediate attention. This report provides an overview of the threat, its operating methods, symptoms of infection, and a step-by-step guide on how to remove it from your system.

What Is Trojan.Stealer.CP?

Trojan.Stealer.CP is a type of malware that falls under the broader category of Trojans, which are malicious programs designed to infiltrate and compromise computer systems. The name "Trojan" originates from the Trojan Horse legend, symbolizing how these malware types disguise themselves as harmless or useful software to gain unauthorized access to a system. The specific designation ".Stealer.CP" suggests that this malware may be designed to steal sensitive information from the infected computer, though the exact nature and capabilities of Trojan.Stealer.CP can vary.

How Trojan.Stealer.CP Operates

Malware like Trojan.Stealer.CP typically operates by exploiting vulnerabilities in software or by tricking users into installing it, often through deceptive downloads or email attachments. Once installed, it can perform a variety of malicious actions, including but not limited to, stealing personal data, monitoring user activity, and potentially installing additional malware. The specifics of how Trojan.Stealer.CP operates can depend on its design and the intentions of its creators, but the general goal is to compromise the security and integrity of the infected system for malicious gain.

Symptoms of Infection

Symptoms of a Trojan.Stealer.CP infection can vary, but common indicators include unusual system behavior, such as slow performance, frequent crashes, or the appearance of unwanted programs or toolbars in your web browser. You might also notice that your personal files are being accessed or modified without your permission, or that your antivirus software is disabled. Sometimes, the infection may not exhibit noticeable symptoms, making it difficult to detect without a thorough system scan.

How to Remove Trojan.Stealer.CP

  1. Enter Safe Mode with Networking: This will limit the malware's ability to interfere with the removal process. Restart your computer and press the key to enter the boot menu (this key varies by manufacturer but is often F12, F2, or Del). Select the option to boot into Safe Mode with Networking.
  2. Conduct a Full Scan with a Reputable Tool: Use a trusted antivirus or anti-malware program, such as SpyHunter, to perform a full scan of your system. This will help identify and remove the malware and any associated files.
  3. Uninstall Suspicious Programs: Go through your installed programs and uninstall any that you do not recognize or that were installed around the time of the infection.
  4. Reset Your Web Browsers: Resetting Chrome, Firefox, Edge, or any other browsers you use can help remove any malicious extensions or settings changes made by the malware. You can usually find the reset option in the browser's settings or preferences menu.
  5. Reboot and Re-scan: After completing the above steps, restart your computer in normal mode and perform another full scan with your antivirus software to ensure that all remnants of the malware have been removed.

Conclusion

Removing Trojan.Stealer.CP from your system requires careful and thorough action to ensure that all components of the malware are eliminated. By following the steps outlined in this report and maintaining vigilant security practices, such as regularly updating your software, using strong antivirus protection, and being cautious with email attachments and downloads, you can protect your system from future infections. Remember, prevention and prompt action are key to minimizing the impact of malware threats.

Analysis Report

General information

Family Name: Trojan.Stealer.CP
Signature status: No Signature

Known Samples

MD5: 783a0673b2026f34390ce4748b705c90
SHA1: 34c2f0d60a35ebfe87cd1f04912957cddaf57901
File Size: 1.26 MB, 1257984 bytes
MD5: 4b3851cfb2dbb286be911a87162e7188
SHA1: 05b34b88c327fcea20ea71f94b2aea92c585d053
SHA256: 2D56D784BBC2F4E6A25ED4E7E3BB629FCEAA73AFBFDF229657B5B544B3B1FEF2
File Size: 363.56 KB, 363555 bytes
MD5: e5d7a8c2fd5f1c6bfb46afb2575e7279
SHA1: 009fcb74467cff121b111657dc8e8303c1ea2e2e
SHA256: 4758CE60FCDCA462AD3D0CBEC9E0D6DFE0ED4FABE9F431716651831BD650F520
File Size: 3.49 MB, 3493026 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File has TLS information
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name
  • GitHub
  • Hashereware (hashereware.com)
File Description
  • Hollows Hunter: scans running processes, recognizes and dumps a variety of potentially malicious implants.
  • Update
File Version
  • 1.1.1.0
  • 0.4.0.0
Internal Name
  • hollows_hunter.exe
  • Update.exe
Legal Copyright
  • Copyright © 2018-2024 Hasherezade
  • Copyright © GitHub 2013-2015
Original Filename
  • hollows_hunter.exe
  • Update.exe
Product Name
  • Hollows Hunter
  • Update
Product Version
  • 1.1.1.0
  • 0.4.0.0

File Traits

  • big overlay
  • No Version Info
  • ntdll
  • VirtualQueryEx
  • WriteProcessMemory
  • x64

Block Information

Total Blocks: 1,018
Potentially Malicious Blocks: 15
Whitelisted Blocks: 959
Unknown Blocks: 44

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x x 0 x 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 ? x x ? x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 1 0 1 0 2 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Downloader.UA
  • Gamehack.EDD
  • PSW.Agent.PF
  • ShellcodeRunner.G

Files Modified

File Attributes
c:\jenkins\workspace\win-xenguestagent_master\src\xendeprivclient\obj\release\xendpriv.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\advapi32.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\bcrypt.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\bcryptprimitives.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\clr.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\clrjit.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\combase.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\comctl32v582.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\cryptbase.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\cryptsp.pdb Read Attributes,Synchronize,Write Attributes
Show More
c:\users\user\downloads\dll\advapi32.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\dll\bcrypt.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\dll\bcryptprimitives.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\dll\clr.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\dll\clrjit.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\dll\combase.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\dll\comctl32v582.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\dll\cryptbase.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\dll\cryptsp.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\dll\dwrite.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\dll\edputil.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\dll\gdi32.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\dll\gdi32full.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\dll\gdiplus.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\dll\imm32.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\dll\kernel.appcore.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\dll\kernel32.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\dll\kernelbase.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\dll\microsoft.visualbasic.ni.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\dll\mscoree.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\dll\mscoreei.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\dll\mscorlib.ni.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\dll\msctf.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\dll\msvcp_win.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\dll\msvcrt.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\dll\ntdll.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\dll\ole32.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\dll\oleaut32.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\dll\profapi.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\dll\rpcrt4.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\dll\rsaenh.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\dll\sechost.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\dll\shcore.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\dll\shell32.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\dll\shlwapi.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\dll\system.configuration.ni.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\dll\system.core.ni.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\dll\system.drawing.ni.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\dll\system.ni.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\dll\system.windows.forms.ni.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\dll\system.xml.ni.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\dll\ucrtbase.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\dll\ucrtbase_clr0400.amd64.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\dll\user32.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\dll\uxtheme.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\dll\vcruntime140_1_clr0400.amd64.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\dll\vcruntime140_clr0400.amd64.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\dll\version.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\dll\win32u.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\dll\windows.storage.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\dll\wldp.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\dwrite.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\edputil.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\exe\xendpriv.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\gdi32.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\gdi32full.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\gdiplus.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\imm32.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\kernel.appcore.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\kernel32.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\kernelbase.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\microsoft.visualbasic.ni.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\mscoree.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\mscoreei.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\mscorlib.ni.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\msctf.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\msvcp_win.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\msvcrt.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\ntdll.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\ole32.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\oleaut32.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\profapi.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\rpcrt4.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\rsaenh.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\sechost.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\shcore.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\shell32.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\shlwapi.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\symbols\dll\advapi32.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\symbols\dll\bcrypt.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\symbols\dll\bcryptprimitives.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\symbols\dll\clr.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\symbols\dll\clrjit.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\symbols\dll\combase.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\symbols\dll\comctl32v582.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\symbols\dll\cryptbase.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\symbols\dll\cryptsp.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\symbols\dll\dwrite.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\symbols\dll\edputil.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\symbols\dll\gdi32.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\symbols\dll\gdi32full.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\symbols\dll\gdiplus.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\symbols\dll\imm32.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\symbols\dll\kernel.appcore.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\symbols\dll\kernel32.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\symbols\dll\kernelbase.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\symbols\dll\microsoft.visualbasic.ni.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\symbols\dll\mscoree.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\symbols\dll\mscoreei.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\symbols\dll\mscorlib.ni.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\symbols\dll\msctf.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\symbols\dll\msvcp_win.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\symbols\dll\msvcrt.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\symbols\dll\ntdll.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\symbols\dll\ole32.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\symbols\dll\oleaut32.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\symbols\dll\profapi.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\symbols\dll\rpcrt4.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\symbols\dll\rsaenh.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\symbols\dll\sechost.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\symbols\dll\shcore.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\symbols\dll\shell32.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\symbols\dll\shlwapi.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\symbols\dll\system.configuration.ni.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\symbols\dll\system.core.ni.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\symbols\dll\system.drawing.ni.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\symbols\dll\system.ni.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\symbols\dll\system.windows.forms.ni.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\symbols\dll\system.xml.ni.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\symbols\dll\ucrtbase.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\symbols\dll\ucrtbase_clr0400.amd64.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\symbols\dll\user32.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\symbols\dll\uxtheme.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\symbols\dll\vcruntime140_1_clr0400.amd64.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\symbols\dll\vcruntime140_clr0400.amd64.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\symbols\dll\version.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\symbols\dll\win32u.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\symbols\dll\windows.storage.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\symbols\dll\wldp.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\symbols\exe\xendpriv.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\system.configuration.ni.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\system.core.ni.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\system.drawing.ni.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\system.ni.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\system.windows.forms.ni.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\system.xml.ni.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\ucrtbase.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\ucrtbase_clr0400.amd64.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\user32.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\uxtheme.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\vcruntime140_1_clr0400.amd64.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\vcruntime140_clr0400.amd64.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\version.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\win32u.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\windows.storage.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\wldp.pdb Read Attributes,Synchronize,Write Attributes
c:\users\user\downloads\xendpriv.pdb Read Attributes,Synchronize,Write Attributes

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtDeleteAtom
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtFreeVirtualMemory
Show More
  • ntdll.dll!NtGetCompleteWnfStateSubscription
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSymbolicLinkObject
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryObject
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySymbolicLinkObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadVirtualMemory
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnlockVirtualMemory
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetThreadState
Other Suspicious
  • AdjustTokenPrivileges
Process Manipulation Evasion
  • ReadProcessMemory

Trending

Most Viewed

Loading...