Threat Database Worms Worm.FakeDoc.A

Worm.FakeDoc.A

By CagedTech in Worms

Threat Scorecard

Popularity Rank: 14,249
Threat Level: 50 % (Medium)
Infected Computers: 752
First Seen: August 1, 2018
Last Seen: July 14, 2026
OS(es) Affected: Windows

The detection of Worm.FakeDoc.A on your system indicates a potential security threat that requires immediate attention. This worm, as indicated by its name, may masquerade as a legitimate document or file to deceive users into executing it, thereby initiating its malicious activities. Understanding what Worm.FakeDoc.A is, how it operates, its symptoms, and how to remove it are crucial steps in safeguarding your computer and sensitive information.

What Is Worm.FakeDoc.A?

Worm.FakeDoc.A is identified as a worm, a type of malware that can replicate itself and spread to other computers without the need for human interaction. The name suggests it may pretend to be a document to trick users, but without specific details, it's essential to approach this threat with a general understanding of worm behavior and removal strategies. Worms can cause significant damage by consuming system resources, stealing information, and creating backdoors for other malware.

How Worm.FakeDoc.A Operates

Worms like Worm.FakeDoc.A typically operate by exploiting vulnerabilities in operating systems or applications to gain unauthorized access. Once inside a system, they can create copies of themselves and spread through network connections, email attachments, or infected software downloads. They may also modify system settings, disable security software, and install additional malware to further compromise the system's security and integrity.

Symptoms of Infection

Symptoms of a worm infection can vary but often include noticeable slowdowns in system performance, frequent crashes, and unusual network activity. You might also observe unfamiliar programs or icons on your desktop, changes in your browser's homepage or search engine, and pop-ups or spam emails being sent from your accounts without your knowledge. Identifying these symptoms early can help in containing the damage and facilitating a more straightforward removal process.

How to Remove Worm.FakeDoc.A

  1. Boot your computer in Safe Mode with Networking to limit the worm's ability to spread or interfere with the removal process.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove all instances of Worm.FakeDoc.A and any associated malware.
  3. Manually uninstall any suspicious programs or applications that were installed around the time of the infection.
  4. Reset your web browsers (Chrome, Firefox, Edge) to their default settings to remove any malicious extensions or changes made by the worm.
  5. Reboot your computer and run another full scan to ensure that all malware has been successfully removed and that your system is clean.

Conclusion

Removing Worm.FakeDoc.A requires a systematic approach to ensure all components of the malware are eliminated from your system. By following the steps outlined above and maintaining vigilance through regular system scans and updates, you can protect your computer from future infections. It's also crucial to practice safe computing habits, such as avoiding suspicious downloads and attachments, to minimize the risk of malware infections. Remember, staying informed and proactive is key to safeguarding your digital environment.

Analysis Report

General information

Family Name: Worm.FakeDoc.A
Signature status: No Signature

Known Samples

MD5: f7bd3f6683de19d901e6ea81338dc21d
SHA1: 4547b3f06a186cbcd419b43eae4befb4a7d9e2de
SHA256: 82ED4E18EA90D892888D6ADBC8C36E5EFCF047BC4D2D09B9D63BED93FA93D24B
File Size: 1.64 MB, 1644032 bytes
MD5: f7b3b5a8d3a7db8677b277fa7c4986f5
SHA1: 0e7a0c6914a0aea0271530f643d9c3ea309699d8
SHA256: 1DBA51ABA2B7A93BC848D98774AEBA83BFDEBD7CD0BBF81B49435D8FB67E940C
File Size: 1.64 MB, 1640448 bytes
MD5: c1c94b9e1ee6f29bce1264a1154bb1e7
SHA1: 33f2f4433bb446a4d467fc5065fcfda1d74a5138
SHA256: 79017BAFCCF347C1C608014B3283A65064923EF4361484490E3B534A03871447
File Size: 1.65 MB, 1651712 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

File Traits

  • HighEntropy
  • No Version Info
  • x86

Block Information

Total Blocks: 3,436
Potentially Malicious Blocks: 96
Whitelisted Blocks: 3,340
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x x 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x x x x x 0 x x x 0 0 x x x x 0 x 0 0 0 0 0 0 0 0 0 x 0 x x x 0 0 0 0 x x 0 0 0 0 0 x 0 x x x x x x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x 0 x 0 0 0 0 0 0 0 0 0 0 x x x x x x x 0 0 x x x x x x x x x x 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 1 0 1 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 2 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 0 0 1 1 0 0 0 0 0 0 0 0 1 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 1 0 3 1 1 1 1 1 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 1 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • FakeDoc.A

Files Modified

File Attributes
\device\namedpipe\46a9cbd7-15c4-44d7-a660-dd80f2816db6 Generic Read,Write Data,Write Attributes,Write extended,Append data
\device\namedpipe\srvsvc Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\194261003.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\194261003.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\local\temp\194261003.tmp Synchronize,Write Data
c:\users\user\appdata\local\temp\1967512794.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\1967512794.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\local\temp\1967512794.tmp Synchronize,Write Data
c:\users\user\appdata\local\temp\2634824180.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\2634824180.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
Show More
c:\users\user\appdata\local\temp\2634824180.tmp Synchronize,Write Data
c:\users\user\appdata\local\temp\rcx29df.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\rcx29ff.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\rcxad9c.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\rcxadad.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\rcxed42.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\rcxed52.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\rac\mls.exe Synchronize,Write Data
c:\users\user\appdata\roaming\rac\svcsc.exe.config.tmp Generic Write,Read Attributes
c:\users\user\downloads\0e7a0c6914a0aea0271530f643d9c3ea309699d8_0001640448.rtf Generic Write,Read Attributes
c:\users\user\downloads\0e7a0c6914a0aea0271530f643d9c3ea309699d8_0001640448.rtf Synchronize,Write Attributes
c:\users\user\downloads\33f2f4433bb446a4d467fc5065fcfda1d74a5138_0001651712.docx Generic Write,Read Attributes
c:\users\user\downloads\33f2f4433bb446a4d467fc5065fcfda1d74a5138_0001651712.docx Synchronize,Write Attributes
c:\users\user\downloads\4547b3f06a186cbcd419b43eae4befb4a7d9e2de_0001644032.docx Generic Write,Read Attributes
c:\users\user\downloads\4547b3f06a186cbcd419b43eae4befb4a7d9e2de_0001644032.docx Synchronize,Write Attributes

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\run::mls "C:\Users\Ipclzdzg\AppData\Roaming\RAC\mls.exe" -s RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\explorer::slowcontextmenuentries `$�!�:i��+00��� Gs]XM���"�2��FXD�':D��exA-��LG=�A��J� �C� RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\explorer::slowcontextmenuentries `$�!�:i��+00��� Gs]XM���"�2��FXD�':D��exA-����n����<��� RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\explorer::slowcontextmenuentries `$�!�:i��+00��� Gs]XM���"�2��FXD�':D��exA-����n����<��� RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\explorer::slowcontextmenuentries `$�!�:i��+00��� Gs]XM���"�2��FXD�':D��exA-����n����<��� RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\explorer::slowcontextmenuentries `$�!�:i��+00��� Gs]XM���"�2��FXD�':D��exA-����n����<��� RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
Show More
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\local settings\software\microsoft\windows\shell\muicache::c:\program files (x86)\windows nt\accessories\wordpad.exe.friendlyappname WordPad RegNtPreCreateKey
HKCU\local settings\software\microsoft\windows\shell\muicache::c:\program files (x86)\windows nt\accessories\wordpad.exe.applicationcompany Microsoft Corporation RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 k�\x +� �� xy ���������%���5��Bx�<���R!wz#@�#��$¨%:�%f�(�*9*�"0P%1HO1�D5,]6�^9�9ߔ=�>3�@V�@ڙ@��A��B��J��K�iN$N�R20R�JU_*\te`�2c�wd��g��lR n�Ap��rnJr�Btu�u�~v�! RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 �� xy�ރ��^��zGVs} kP~ ��1C��e0��1�� RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\applets\wordpad\options::wrap  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\applets\wordpad\options::showstatusbar  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\applets\wordpad\options::showruler  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\applets\wordpad\options::units RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\applets\wordpad\options::maximized RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\applets\wordpad\options::framerect RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\applets\wordpad\options::pagemargin ܈֠܈֠ RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\applets\wordpad\options::printpagenum  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\applets\wordpad\options::defaultformat  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::mls "C:\Users\Pdwyfokh\AppData\Roaming\RAC\mls.exe" -s RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\explorer::slowcontextmenuentries `$�!�:i��+00��� Gs]XM���"�2��FXD�':D��exA-����n����<��� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 hi\x +� �� xy �� ۀ�������%��Bx�<���R#@�#��$¨%f�(�)E*9*�"0P%1HO5,]9�@V�@ڙ@��B��J��N$N�U_*VN�\tec�wd��g��n�Ao��rnJu�~v�!y�y�9y�^|ۘ~D���P����jI�����|��7��a��3 RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 ��ރ#Vs} kP~ ��1��ee��0��1��ie��r2�ve�� RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::mls "C:\Users\Hbszymfd\AppData\Roaming\RAC\mls.exe" -s RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\explorer::slowcontextmenuentries `$�!�:i��+00��� Gs]XM���"�2��FXD�':D��exA-����n����<��� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �l= �vT���������3bBx�R%`�(�(X�*J1�1HO@V�A��G�IH[u_�zb"hc�zh�rj�bk�ql(�q�Xvy�w�n{b��P��jI�/�����b:�������6�X�����.���a ������*� [�m�Ù��'N�]�����$�8�fწ���V��j RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 陲ȁਪˣ鈯ˣ遙̃豤̃অˣ炑̃濖̃賬̃獖}਷ˣ邯̃뫯ʃ RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �lD �v��T���������3bBx�R%`�(�(X�*J1�1HO@V�A��G�IH[u_�zb"hc�zh�rj�bk�ql(�q�Xvy�w�n{b��P��jI�/������7�M�b:�������6�X�����.�Θ���a ������*� [�m�Ù��'N�]��IV����$�8 RegNtPreCreateKey

Windows API Usage

Category API
Network Winsock2
  • WSAStartup
Process Shell Execute
  • ShellExecute
Process Manipulation Evasion
  • NtUnmapViewOfSection
Other Suspicious
  • SetWindowsHookEx
Network Winsock
  • closesocket
  • connect
  • freeaddrinfo
  • getaddrinfo
  • socket

Shell Command Execution

open 4547b3f06a186cbcd419b43eae4befb4a7d9e2de_0001644032.docx
open C:\Users\Ipclzdzg\AppData\Roaming\RAC\mls.exe -s
open 0e7a0c6914a0aea0271530f643d9c3ea309699d8_0001640448.rtf
open C:\Users\Pdwyfokh\AppData\Roaming\RAC\mls.exe -s
open 33f2f4433bb446a4d467fc5065fcfda1d74a5138_0001651712.docx
Show More
open C:\Users\Hbszymfd\AppData\Roaming\RAC\mls.exe -s

Related Posts

Trending

Most Viewed

Loading...