Kuaizip.A is an Adware. Adware, or advertising-supported software, is any software that automatically renders advertisements in order to generate revenue for its author. The advertisements may be in the user interface of the software or on a screen presented to the user during the installation process. It is usually annoying but harmless, unless it is combined with spyware or trackware.
Mutexes created
Directory level activity
File level activity
Registry level activity
Library level activity- load - library - api-ms-win-core-synch-l1-2-0
- load - library - kernel32
- load - library - api-ms-win-core-fibers-l1-1-1
- load - library - api-ms-win-core-localization-l1-2-1
- load - library - kernel32.dll
- load - library - C:\WINDOWS\system32\rpcss.dll
- load - library - C:\WINDOWS\system32\uxtheme.dll
- load - library - uxtheme.dll
- load - library - api-ms-win-appmodel-runtime-l1-1-1
- load - library - ext-ms-win-kernel32-package-current-l1-1-0
- load - library - mscoree.dll
Process API calls used
- ZwMapViewOfSection
- ExitProcess
Registry API calls used
System API calls used
- LdrLoadDll
- LdrGetProcedureAddress
- LdrGetDllHandle
- IsDebuggerPresent
- LdrGetDllHandle
Filesystem API calls used
Network
UDP source >> destination - 192.168.30.10 >> 192.168.30.255
- 192.168.30.10 >> 8.8.8.8
TCP source >> destination - 192.168.30.10 >> 72.21.91.29
Domains:- s.symcb.com with IP - 72.21.91.29
- sw.symcb.com with IP - 72.21.91.29
DNS Request: HTTP Request:- GET URI - http://s.symcb.com/pca3-g5.crl
- GET URI - http://sw.symcb.com/sw.crl
DLL related data Number of DLL's imported = 9
- USER32.dll
- ole32.dll
- SHLWAPI.dll
- WS2_32.dll
- KERNEL32.dll
- ADVAPI32.dll
- SHELL32.dll
- WLDAP32.dll
- VERSION.dll
|