PUP.AceTools.A

Analysis Report

General information

Family Name: PUP.AceTools.A
Signature status: No Signature

Known Samples

MD5: fe7a4289c65535673fc4f3af7e2fcacf
SHA1: c9046367bb23e04440e01727988e4550e2a51839
SHA256: A3B71476656BBF88D392AD0F89BB6AA4D8E6DF5C4BC0EA2162FB9111E33CC907
File Size: 2.53 MB, 2534166 bytes
MD5: 4466506e207075246d3063cbf8c265f8
SHA1: ad6872c097c49f579101aa9cc10ebfc0d846bb04
SHA256: BAA7F8D605159533A6FD423217F54C2A564CE8A6FDB46F9017D3691E5F12A036
File Size: 2.23 MB, 2231297 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments This installation was built with Inno Setup.
Company Name AceTools.biz
File Description
  • Ace Translator 9.5.4 Installer
  • Ace Translator 11 Installer
File Version
  • 11
  • 9.5.4
Legal Copyright
  • Copyright © 2012 AceTools.biz
  • Copyright © 2013 AceTools.biz
Product Name Ace Translator
Product Version
  • 11
  • 9.5.4

File Traits

  • 2+ executable sections
  • VirtualQueryEx
  • x86

Files Modified

File Attributes
c:\users\user\appdata\local\temp\is-1buck.tmp\ad6872c097c49f579101aa9cc10ebfc0d846bb04_0002231297.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-aito3.tmp\c9046367bb23e04440e01727988e4550e2a51839_0002534166.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-kociv.tmp\_isetup\_setup64.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-kociv.tmp\_isetup\_shfoldr.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-s0r8c.tmp\_isetup\_setup64.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-s0r8c.tmp\_isetup\_shfoldr.dll Generic Read,Write Data,Write Attributes,Write extended,Append data

Windows API Usage

Category API
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
User Data Access
  • GetUserObjectInformation
Keyboard Access
  • GetKeyState

Shell Command Execution

"C:\Users\Msmgjxam\AppData\Local\Temp\is-AITO3.tmp\c9046367bb23e04440e01727988e4550e2a51839_0002534166.tmp" /SL5="$20236,1984471,118784,c:\users\user\downloads\c9046367bb23e04440e01727988e4550e2a51839_0002534166"
"C:\Users\Idryyejo\AppData\Local\Temp\is-1BUCK.tmp\ad6872c097c49f579101aa9cc10ebfc0d846bb04_0002231297.tmp" /SL5="$40060,1691590,140800,c:\users\user\downloads\ad6872c097c49f579101aa9cc10ebfc0d846bb04_0002231297"

Trending

Most Viewed

Loading...