Threat Database Trojans Trojan.Ulise.CA

Trojan.Ulise.CA

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 1,268
Threat Level: 80 % (High)
Infected Computers: 2,241
First Seen: March 4, 2022
Last Seen: July 30, 2026
OS(es) Affected: Windows

Your system has been detected with a threat identified as Trojan.Ulise.CA. This detection indicates that your computer is infected with a type of malicious software that can potentially harm your system and compromise your personal data. It is essential to take immediate action to remove this threat and prevent further damage.

What Is Trojan.Ulise.CA?

Trojan.Ulise.CA is a type of Trojan, which is a broad category of malware that can allow unauthorized access to your system. Trojans are often disguised as legitimate software, but they can cause significant harm by stealing sensitive information, installing additional malware, or providing a backdoor for remote access. The name "Trojan.Ulise.CA" suggests that it may be a variant of a known Trojan, but without more specific information, it's challenging to determine its exact nature or origin.

How Trojan.Ulise.CA Operates

Trojans like Trojan.Ulise.CA typically operate by exploiting vulnerabilities in your system or deceiving you into installing them. Once installed, they can run in the background, hidden from view, and perform various malicious activities. These can include data theft, such as logging keystrokes or capturing screenshots, installing additional malware, or modifying system settings to weaken security. Trojans can also communicate with their command and control servers to receive updates or transmit stolen data.

Symptoms of Infection

Identifying a Trojan infection can be challenging because these malware types are designed to remain stealthy. However, some common symptoms that might indicate your system is infected include unusual system behavior, such as slow performance, frequent crashes, or unfamiliar programs running in the background. You might also notice changes in your browser settings, unexpected pop-ups, or antivirus warnings. In some cases, Trojans can lead to more severe issues, like data loss or identity theft, emphasizing the need for prompt action.

How to Remove Trojan.Ulise.CA

  1. Boot your computer in Safe Mode with Networking. This will help prevent the malware from loading and give you a cleaner environment to work in.
  2. Download and install a reputable anti-malware tool, such as SpyHunter. Run a full scan of your system to detect and remove all instances of the Trojan and any other malware that might be present.
  3. Uninstall any suspicious programs that you don't recognize or that were installed around the time your system became infected. Be cautious and only remove programs you are sure are not needed.
  4. Reset your web browsers (Chrome, Firefox, Edge) to their default settings. This can help remove any malicious extensions or settings changes made by the Trojan.
  5. Reboot your computer and run another full scan with your anti-malware tool to ensure that the Trojan and all associated malware have been successfully removed.

Conclusion

Removing Trojan.Ulise.CA requires careful and immediate action to prevent further damage to your system and protect your personal data. By following the steps outlined above and maintaining good security practices, such as keeping your software up to date, using strong antivirus protection, and being cautious with emails and downloads, you can significantly reduce the risk of future infections. Remember, staying vigilant and proactive is key to safeguarding your digital security in today's evolving threat landscape.

Analysis Report

General information

Family Name: Trojan.Ulise.CA
Signature status: No Signature

Known Samples

MD5: 043c512687c46b79d102a4f158a087a6
SHA1: b4bb1d91bce9fcbee5d4dde35f872cc180125db4
File Size: 1.09 MB, 1089892 bytes
MD5: 8c7e2fcefaa7f452b9718a465ad6cb89
SHA1: 7edf398c1b7eb86361ff204dbfc02730e01bfa43
File Size: 7.99 MB, 7988224 bytes
MD5: 86831b172b6da6c603fe51550491af38
SHA1: ed02bf47c72bfaa81b88806cd0d22c64d215f18b
SHA256: B4A309F6D3B695A83B8FA25D8AF1A8D6E56617D5EE45FE58D7CE3E9F59C4A708
File Size: 4.69 MB, 4688896 bytes
MD5: b89a9a5ac78e6eea2ecf5c306fca1b39
SHA1: 02822ee56c82eb27ae64a23a16e07b1501bae567
SHA256: EA96A73C17ECF7E67422F1A78F22886579FEF9396BF658756EBFE5CBA3BDFA44
File Size: 7.13 MB, 7131858 bytes
MD5: 10bbd5cfbd03eb684275f9db8f8151e4
SHA1: 768cf785942a3681538168f2dc23588aa82bf231
SHA256: A7A4E00D5A891C1E4AB15675EC53ABE2A65C28385D3E76D89F0D1FC2BA1AAD44
File Size: 1.09 MB, 1085796 bytes
Show More
MD5: d0328f0ccdc8bf4e1077256c09a07a4c
SHA1: c461fc0059ba2b7324ce2c9eb2f5fb99ccedfbb4
SHA256: E5EFDD8466EDDE626B4BE6B2539C2609EB4A44AF1FADF24921A0E5E8BA3CD161
File Size: 6.47 MB, 6474752 bytes
MD5: 3bc203bdb7495b7e1b0e67278147b0e3
SHA1: d4ab73eb22276d4598a1acad1ae19d4055aeab20
SHA256: 69536107151F1AA8E1F4941F43D4FF69C7F9B7ABA17A0899CAED286AF283FB62
File Size: 6.81 MB, 6810112 bytes
MD5: 3f9d53ccaeafabfae256de8657a0f456
SHA1: 6658de363e6a3fef6ceca7cf08ebc6bfb25f24d0
SHA256: 7E06F03F8D47B752265DA3846C4806BC1FF7159E0E39C5DB34774DAF5DA91003
File Size: 880.13 KB, 880128 bytes
MD5: 0538194ce8b5d9ec4c3fefd066c4fb41
SHA1: e3bdd14a25f19f2b2217016b3f87509a38f35bb4
SHA256: AD3BB1CA37F52481E1D7F06938041F853CAA9FA0AADDC6BD38A063C247193134
File Size: 7.13 MB, 7125156 bytes
MD5: 5d09416ae2a9c579e91607c23630f8a1
SHA1: 382e00bfea209fb3fae3874a283b2945443bf6ac
SHA256: 09577FA8391A1084D2AD8EA7149D76ACB549D364D669E125C9854FBDD38F414D
File Size: 1.09 MB, 1089892 bytes
MD5: ba2c8a2c6694a1b91c68a4f7764cbfb0
SHA1: 0a0a5d6e02786ea1211bc78938885f11674d380c
SHA256: 57E0470689F396F6F22D76C302912564108C2EA2269A2973866443ACCB146739
File Size: 4.24 MB, 4239125 bytes
MD5: a66ee33c2d49351766b0ee7bfefeef71
SHA1: 99042539b94ac1c0bea54f68304cae561bd61ffb
SHA256: 5CEB2A81BC43FCB374C5F15489DF8CBB7D357D1A3F58DF233DB6689BBE5AB297
File Size: 4.88 MB, 4883640 bytes
MD5: d7011d9b20bbc8638e44b723a6b434f7
SHA1: f99148c58ad60d8c35ee78bb01238cf13b0c6f8a
SHA256: 245A0D883B5EFC79CD9EEEBD9DC897DBA8F022555FFE8AE9C1856A75E11A48CA
File Size: 6.39 MB, 6394688 bytes
MD5: 1c7f336e4f0eac6d9cac4a21740677e5
SHA1: a922463da1eef5fe1a5a8f32ba3a64cbd9833ee3
SHA256: 2BD1DBFEE8C7F0C2A8C128EED63416B491DA2C3FCC79244BB2DE7ECE081CCF63
File Size: 1.95 MB, 1946112 bytes
MD5: 614870500f475c81268aebaf5e61fea0
SHA1: 088647438c3a79fe7ec458bccb0fe47b27201c75
SHA256: 74070DD9C86D82D91D7A04A32D48B3FDDECD785BB500D031A7924FA61C5455EA
File Size: 1.01 MB, 1005056 bytes
MD5: a1eec09d3dff54208243bc2e264a6d17
SHA1: 0d5ccf430b0dda4f6cf2552be637464a52f0c9e8
SHA256: 4770B71EF1AC14C9E499BA6A78B8E47AAA2E89783B34F4234A1DE93BB04BD7AA
File Size: 1.14 MB, 1141902 bytes
MD5: 74f8bc3f6f40974b554def7fd196c954
SHA1: bbe840e286d6f24bde7c42e5a75b0f9047671fa5
SHA256: C0D1B0B5E8F900EFAB78ACFAFD0A62DC813515F246F8ED00EABB6C38226E8420
File Size: 2.53 MB, 2531176 bytes
MD5: 752001f82652d76b174f9af2fc4b8a77
SHA1: 076ff45cdc0a37a86f4fa3721e9bb4e502287294
SHA256: 0D2338B748EE3A47B563135DA781299346803CF9BEAE99BFA66C2AB8C3CD04F6
File Size: 1.00 MB, 1003520 bytes
MD5: b0d1143f2190e8703c3de39e2f614151
SHA1: c4f2a9790c820969ec2863356520c0d1496de6ab
SHA256: 94511AF8E4916DE31DA997035FF494F5A7820EDF91CC9D038B519A478B70825A
File Size: 6.89 MB, 6888960 bytes
MD5: 7f23f06b2814f0473f7d4c5af10a0cd9
SHA1: e701e6618e8331896ac54154649631d2269d93f7
SHA256: E00C566F3FF323FCA24587E1A0F2B540D22776C7B3FA8CF3F1B954F1C3E73BD4
File Size: 905.22 KB, 905216 bytes
MD5: f021b0ff5e047a66605ee8e88f1b0e97
SHA1: 9d69624f7158d61fa69176f15f24f2272e150529
SHA256: 30EAB03A091E59C4420C92B714098A3DB52EF811625B203CC689265ED9100168
File Size: 250.88 KB, 250880 bytes
MD5: 6ca958d452a2c21d06cb0bd6b3ac2a56
SHA1: eff0b37a59f8947c60dc5d161be1ffaff4b05e50
SHA256: 323505EF3A83B7D6A526EC04DF8542ECFE647CE2DD5B2FE57652CCF49E0A4061
File Size: 911.87 KB, 911872 bytes
MD5: 6d9497419fa3ab6d2cb8e21278f49d9f
SHA1: aa6b2b9b98c9db8a86b4a2d6d598d4384ad56dff
SHA256: 9A93A24651793E8E30EB6D91B0E4C23C4D7D1489B790E4C13C3B2BA00720B06E
File Size: 1.09 MB, 1085796 bytes
MD5: d0208e2aadb09369ac66c9f1527dcf54
SHA1: 0006e9387432736f1c7bf13fffdd64107e7a646b
SHA256: F343C824C9CB09215EB9D12AAA364F4100DAB3850D603456D0F214274B2B58D8
File Size: 530.43 KB, 530432 bytes
MD5: 644941d7bc5bef2f9327a8ba987abe27
SHA1: 50d3fb5625990c85637f4a6804299b7f126d9a23
SHA256: 2133197D04D75FDC2FE5C3A2B38816BE28C5AF224696704436CC67E1A0DF7C60
File Size: 9.03 MB, 9029632 bytes
MD5: b3f74c9bbedbd6d06534b3da58c2f759
SHA1: b2f9d152a17e4612f2c56b298d2d85094710737a
SHA256: 6CBA01C0F87AC6D53F8AA9D298752B82B86D8991A895AA5AA97BB2F6F05DF050
File Size: 6.08 MB, 6083275 bytes
MD5: 1e10d1b55e262dc95111ab37cba94010
SHA1: 0abbee639095dae69759c482ca7304adf08d9445
SHA256: A1084465135860817C4F89110F9EADDC582D7452D37864B7E1E74E2EC2188738
File Size: 2.78 MB, 2775040 bytes
MD5: a7ce50c39ccaa4f725187a4351f37b11
SHA1: f3ceb303dd781c29616d9ad3ea24f91515a9cd50
SHA256: E590FCBDF7741201BCD44FE56BC3D423AB814A469DCC7677DB8DF608D90F24B0
File Size: 3.90 MB, 3903502 bytes
MD5: acfc04c6397d692194642de3910c4c9c
SHA1: cd2a5e3a6b352bd952620ac916969bdbf81f72d2
SHA256: A4382D3D2F77DDD34E9A78E10980D638E0F8A2DA03C3DA31B2533195B717DE83
File Size: 4.69 MB, 4686336 bytes
MD5: ad84d0bbaefaf2208fd1affb142e46b1
SHA1: aa9ef59a46c8260f3f8d81cd77a77b84ec396bed
SHA256: 72C2D4C98BAE4E26F7A21F3C0D7621444021F2E31D0AC34E6399A463E045D86B
File Size: 419.33 KB, 419328 bytes
MD5: 9c4c88dec009a71c14291d013d6bb0cd
SHA1: 5040b43882248f969e794f1b0cafb82acf7b0b32
SHA256: 73DC4A9B1D8677222DE54BA0935BDAFD40AADF75A1E8F5C49D5A12852A82382D
File Size: 1.09 MB, 1089892 bytes
MD5: f88f628113015d256160a9707fe53ddb
SHA1: b5f525875f50d46f3f6853cbf527164d99b9e2c8
SHA256: E50201E9DA20A6CC3C3F100D279E02F37F6C9D52A3517B473CF83B166013A5D4
File Size: 3.52 MB, 3520000 bytes
MD5: bcdc69d2513b5ff2bb2d6a0466a7c394
SHA1: 6aebf9449b224ae0a37d929a6ddc94490c10517a
SHA256: EC123AC19A2E75C54B48DF8AE044A93EA8D36B8F78EFE782FF1FC9612CA5A698
File Size: 1.01 MB, 1007616 bytes
MD5: 701e77a326a6099be4ee247b4f3bf75d
SHA1: 362ea26920dd8fe3cf16f03cc38ecf37375ea8be
SHA256: 71333DC9B7E094927E0BA99E681D7AA5990187B343707729FCBF16D9E671EAC3
File Size: 1.09 MB, 1089892 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have resources
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
Show More
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Show More

Windows PE Version Information

Name Value
Assembly Version
  • 3.3.0.0
  • 2.1.1.35388
  • 2.0.0.0
  • 1.3.11.0
  • 1.0.0.0
Comments
  • BURIKO General Interpreter uses the OggVorbis libraries. The OggVorbis libraries are Copyright (C) 1994-2002 by the Xiph.Org Foundation. < http://www.xiph.org/ >
  • Email: bylandtech@yeah.net
  • FurMark - GPU burn-in utility and OpenGL benchmark
  • http://www.gzoso.com
  • Packed portable application inside
  • XirDecoder Company AI Solutions - support@xirdecoder.com
Company Name
  • BURIKO Co.,Ltd.
  • Cyber247.VN
  • Geeks3D (www.geeks3d.com)
  • Longsys
  • Matin
  • SerGreen
  • Wondershare
  • www.ChronoCrash.com
  • XirDecoder Company
  • Ymir Entertainment
Show More
  • 绿色系统
File Description
  • BMB V6 2022
  • Ethornell - BURIKO General Interpreter
  • EVGA XR1 RGB Installation
  • Fix_Iklan_Android
  • FurMark - GPU stress test and OpenGL benchmark
  • Longsys repaire box
  • Matin Repair Box
  • Menu Game
  • Metin2Client
  • Mi_Flash_No_Auth
Show More
  • mss
  • RFt
  • TCP/UDP测试工具
  • Ultimate 2D Game Engine
  • UmiTeam Remote Tool
  • Wondershare PDF Password Remover
  • XirDecoder
  • 绿色系统软件安装管理
File Version
  • Version : 1.656.3 - Compatibility : 1.72
  • Softprep
  • 8.0.0.5
  • 3.3.0.0
  • 2.1.1.35388
  • 2.0.0.0
  • 1.18.0.0
  • 1.5.0.0
  • 1.3.11.0
  • 1.00
Show More
  • 1.0.34669.1
  • 1.0.0.5
  • 1.0.0.0
  • 1.0
Internal Name
  • BMB V6 2022.exe
  • Ethornell
  • FurMark
  • Menu Game.exe
  • Metin2Client
  • mss.exe
  • Open Beats of Rage
  • PDFPasswordRemover.exe
  • RepairBox.exe
  • RFt.exe
Show More
  • tcpudp_2.1.1.exe
  • TJprojMain
  • UmiTeam Remote Tool.exe
  • UnpackerWindowless.exe
  • Xir_Auto_Option.exe
Legal Copyright
  • (c) <Longsys>. All rights reserved.
  • (c) <Matin>. All rights reserved.
  • Copyright (C) 2007-2016 Geeks3D (www.geeks3d.com)
  • Copyright (C) 2007-2020 BURIKO Co.,Ltd.
  • Copyright (C) 2011
  • Copyright(c) 2020 EVGA Corp.All rights
  • Copyright © 2018-2021
  • Copyright © 2022
  • Copyright © 2023
  • Copyright © 2023 - 2026
Show More
  • Copyright © 2025
  • OpenBOR
  • Wondershare PDF Password Remover
Legal Trademarks
  • BURIKO General Interpreter
  • OpenBOR
  • Wondershare PDF Password Remover
Original Filename
  • BGI.exe
  • BMB V6 2022.exe
  • BOR
  • FurMark.exe
  • Menu Game.exe
  • Metin2Client.exe
  • mss.exe
  • PDFPasswordRemover.exe
  • RepairBox.exe
  • RFt.exe
Show More
  • tcpudp_2.1.1.exe
  • TJprojMain.exe
  • UmiTeam Remote Tool.exe
  • UnpackerWindowless.exe
  • Xir_Auto_Option.exe
  • XR1.exe
Product Name
  • Appacker
  • BMB V6 2022
  • EVGA XR1 RGB
  • FurMark
  • Menu Game
  • Metin2Client
  • mss
  • OpenBOR
  • Project1
  • RepairBox
Show More
  • RFt
  • TCP/UDP测试工具
  • UmiTeam Remote Tool
  • Wondershare PDF Password Remover
  • XirDecoder Company
Product Version
  • 8.0.0.5
  • 3.3.0.0
  • 3.0
  • 2.1.1.35388
  • 2.0.0.0
  • 1.18.0.0
  • 1.3.11.0
  • 1.00
  • 1.0.0.5
  • 1.0.0.0
Show More
  • 1, 0, 0, 1

Digital Signatures

Signer Root Status
EVGA Corp. DigiCert EV Code Signing CA (SHA2) Self Signed

File Traits

  • 2+ executable sections
  • Default Version Info
  • dll
  • Enigma
  • HighEntropy
  • No Version Info
  • ntdll
  • WriteProcessMemory
  • x86
  • Zprotect

Block Information

Total Blocks: 3,026
Potentially Malicious Blocks: 2
Whitelisted Blocks: 2,948
Unknown Blocks: 76

Visual Map

? 0 0 0 0 0 ? 0 0 ? ? 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? ? ? ? ? ? ? ? ? 0 ? ? ? ? 0 ? 0 ? ? ? 0 ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? 0 0 ? 0 0 0 0 0 ? 0 ? 0 ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? ? ? 0 0 ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 2 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 1 1 1 0 3 1 1 2 3 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 2 0 0 0 0 0 0 0 0 0 1 1 1 0 0 0 0 0 0 0 0 1 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 1 0 0 0 0 1 1 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 2 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Gamehack.AAD
  • Kryptik.RAR
  • Kryptik.RAU

Files Modified

File Attributes
c:\users\user\appdata\local\temp\evb5153.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsl963b.tmp\modern-wizard.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsl963b.tmp\modern-wizard.bmp Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nsl963b.tmp\nsdialogs.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsl963b.tmp\system.dll Generic Write,Read Attributes

Windows API Usage

Category API
Other Suspicious
  • SetWindowsHookEx
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
User Data Access
  • GetUserObjectInformation
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtQueryAttributesFile
Show More
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWriteFile
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\9d69624f7158d61fa69176f15f24f2272e150529_0000250880.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\6aebf9449b224ae0a37d929a6ddc94490c10517a_0001007616.,LiQMAxHB