Threat Database Malware HackTool:Win32/Welevate

HackTool:Win32/Welevate

By ZulaZuza in Malware

Threat Scorecard

Popularity Rank: 17,365
Threat Level: 50 % (Medium)
Infected Computers: 1,092
First Seen: November 5, 2012
Last Seen: December 31, 2025
OS(es) Affected: Windows

HackTool:Win32/Welevate is a malignant program that targets 32-bit computer systems. HackTool:Win32/Welevate is also used by fake anti-spyware applications. HackTool:Win32/Welevate may show a bogus pop-up warning message on the screen of the corrupted PC. HackTool:Win32/Keygen may seem to be a legitimate program; however in reality, it is a security risk to computer security because it can make the affected computer system to malfunction. HackTool:Win32/Welevate enables cybercriminals to perform illegitimate activities on the infected computer. HackTool:Win32/Welevate may also drop malicious files and reduce the PC's performance.

Analysis Report

General information

Family Name: PUP.HackKMS.AB
Signature status: No Signature

Known Samples

MD5: 588e6b1118a58fd5d78199cd4fb05cf4
SHA1: c3f52653b131ccad0df9c2b320fcad45dc0c3da9
SHA256: B332F66BB9E94F9B0E7C24316842E27C8E760FFAFECB98ABDE0B1B51BFA8493F
File Size: 38.45 KB, 38454 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have resources
  • File doesn't have security information
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • HighEntropy
  • No Version Info
  • x86

Block Information

Total Blocks: 49
Potentially Malicious Blocks: 42
Whitelisted Blocks: 7
Unknown Blocks: 0

Visual Map

x x x x x x x x 0 x x x x x x 0 x x x 0 x x x x x x x x x x x x x 0 x x x x x x x x x x x x 1 1 1
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • HackKMS.A
  • HackKMS.AB
  • HackKMS.LL

Windows API Usage

Category API
Service Control
  • StartServiceCtrlDispatcher

Trending

Most Viewed

Loading...