PUP.Aman VPN

Threat Scorecard

Popularity Rank: 4,520
Threat Level: 10 % (Normal)
Infected Computers: 34,331
First Seen: March 22, 2022
Last Seen: January 27, 2026
OS(es) Affected: Windows

SpyHunter Detects & Remove PUP.Aman VPN

File System Details

PUP.Aman VPN may create the following file(s):
# File Name MD5 Detections
1. aman/amanonlinewt.exe ed4ac1dadf95ba62b89322ba351bdc13 10,865
2. AmanUpdateLogLT.exe bc414a73a6c6bed20cd8f5401f727864 7,793
3. amanProxy.exe 80f0297c285d9731e9d7a797b6e67315 1,170
4. Aman_2.3.5.0907_1237.exe 8e91c8c37ea048ad45a27c172dd9471b 981
5. aman/amanupdateloglt.exe 60bef1ec460e8ee5dcb468117412bddb 265
6. Aman_2.2.8_oem_10015.exe dfa2bd7028aa1ea2e4e6c35b15a12c2f 251
7. AmanOnlineWT.exe fb1098b9fc84c85d0b28e75783d422be 204
8. Aman_2.3.6.1116_1440.exe b17a2ca04543a47f2796220161a78dc5 138
9. Aman_2.1.9.0513_1309.exe 3912a20728956ec2e9c83a104c341d42 88
10. LocalT.exe f065af613dce076c0ad8f48e2fc1de9b 83
11. Aman_2.1.8_oem_10015.exe 4064741d443fe923132b175ad3281fc8 75
12. Aman_2.2.2.0527_1254.exe c0472e7e1b473f7239f7891abadc9559 66
13. Aman.exe 2ea49798003b55872dd3b750976bc518 49
14. loadAman.exe 3c6ddd68e6a42ccadb1866ee5285b390 48
15. Aman_2.3.7.05201736.exe 56035ccde880a778c5e23d4c1d166918 41
16. Update.exe 3a771198070204c9bad749e087c57fe5 13
17. Aman_2.1.1_03311020.exe 0ea795fc1b0c8d1a113776a1242c667f 12
18. UpdateTemp.exe 3e8b1ed79a9391fb38a40961894c9a30 9
19. Install.exe 7aa7cd6f1a3ad7bb61105a3bf1067e63 8
20. freeloop.exe 3878955d791d8ad71b61fa0cbf88085b 5
21. wt.exe 989916732acd4bbbe60e6df8dc0c53a0 3
22. Aman_2.2.1.0526_2205.exe 59ce332873d5398973f9551ec98dc1df 3
23. Aman_2.0.8_03281652.exe 0102316893905b3cfbbd0e7c7fbe34d2 2
24. Aman_2.1.4_04121209.exe f0cbd19370d694e3fd67f34603aecb9a 2
25. Aman_2.0.7_03261535.exe 7157004cc93f5fb7a803677642336ae3 1
More files

Analysis Report

General information

Family Name: PUP.Aman VPN
Signature status: Root Not Trusted

Known Samples

MD5: a35cac044e4aebe628ce5b36e125e36c
SHA1: 03fe78e027f6eab3656e15dc938345be8dd60a6f
SHA256: 9F96B84FFF44ACD087A07D75F6B2442EED004B7C9998BAB134B4BC11AF63A575
File Size: 1.04 MB, 1043744 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File has TLS information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name HONGKONG LINGYUN MDT INFOTECH LIMITED
File Description GalleonVPN
File Version 3.0.0.0421
Legal Copyright Copyright (C) 2021 Hongkong LINGYUN NetWork Technology Co., Ltd.
Original Filename GalleonVPN.exe
Product Name GalleonVPN.exe
Product Version 3.0.0.0421

Digital Signatures

Signer Root Status
HONGKONG LINGYUN MDT INFOTECH LIMITED DigiCert Trusted Root G4 Root Not Trusted

Block Information

Total Blocks: 1,994
Potentially Malicious Blocks: 0
Whitelisted Blocks: 1,412
Unknown Blocks: 582

Visual Map

0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 ? 0 0 ? ? ? ? 0 ? ? 0 ? ? ? ? ? ? 0 0 ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 ? 0 ? ? 0 0 0 0 ? 0 ? ? 0 ? 0 0 0 0 ? ? 0 0 ? 0 0 0 ? 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 ? 0 ? ? 0 0 0 0 1 ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 ? 0 ? ? 0 0 ? ? 0 0 0 0 ? 0 ? ? ? 0 0 0 0 0 0 0 ? ? ? 0 0 ? ? ? ? 0 ? ? ? ? ? 0 0 0 0 ? 0 0 ? ? ? ? ? 0 0 ? ? ? ? 0 ? ? ? 0 ? ? 0 ? ? ? ? ? ? ? 0 0 0 ? ? ? 0 0 ? ? 0 0 0 ? 0 0 0 0 0 0 0 ? ? ? 0 0 ? ? ? ? 0 ? ? ? ? 0 ? 0 0 0 ? ? 0 0 ? ? 0 0 0 ? 0 0 0 0 0 0 0 0 ? 0 0 ? ? ? ? ? ? ? 0 ? 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 ? ? ? ? 0 0 0 0 0 0 0 ? ? ? ? 0 ? 0 ? 0 0 ? ? 0 0 0 0 ? ? 0 0 0 ? 0 0 0 0 0 ? 0 ? 0 ? 0 ? ? ? 0 ? 0 ? ? 0 0 ? ? ? ? ? 0 ? ? ? 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 0 ? 0 0 0 0 0 ? ? 0 0 0 0 0 ? 0 0 0 ? ? ? 0 0 0 0 0 0 ? 0 ? 0 0 ? ? ? 0 0 0 ? 0 ? ? ? ? ? ? 0 ? ? 0 ? ? 0 ? ? ? 0 ? 0 ? 0 0 0 ? ? ? ? 0 0 ? 0 0 0 0 0 0 0 ? 0 ? ? 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? 0 0 0 ? ? 0 0 ? ? 0 0 0 ? 0 0 0 0 0 0 ? ? ? ? ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 ? ? ? ? ? ? ? 0 0 0 0 1 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? 0 ? 0 0 0 0 0 0 ? ? 0 ? 0 ? 0 0 0 0 0 0 0 0 ? 0 ? ? ? ? ? ? 0 0 ? ? ? ? ? ? ? 0 0 0 ? 0 0 0 0 0 0 0 0 ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 ? ? 0 0 0 0 ? 0 0 0 0 0 0 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 ? ? ? ? ? ? ? ? 0 ? ? ? 0 ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? 0 0 ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 1 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? 0 ? 0 ? 0 0 0 0 ? ? 0 ? ? 0 ? ? ? 0 ? ? 0 0 0 0 0 0 0 0 ? ? 0 ? 0 0 ? 0 ? ? ? 0 0 ? ? ? 0 ? ? ? ? ? ? ? 0 0 ? ? ? ? ? ? 0 0 0 0 0 0 0 ? ? 0 ? 0 ? 0 0 0 0 0 0 0 0 0 ? ? 0 ? 0 ? ? 0 0 0 0 ? ? ? 0 0 0 0 ? 0 ? ? ? 0 0 0 ? ? ? 0 ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 ? 0 ? ? ? 0 ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? ? ? 0 0 0 0 0 0 ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? 0 ? 0 ? ? ? 0 0 0 ? ? 0 0 ? ? ? ? ? ? 0 ? ? ? ? ? 0 0 0 ? 0 0 ? ? 0 0 0 0 0 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 ? 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 ? 0 0 0 0 ? 0 ? 0 ? 0 0 0 1 0 ? 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 1 0 0 ? ? ? 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 ? 0 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 1 0 0 0 0 0 ? ? ? ? ? ? ? ? 0 0 0 0 0 0 2 0 2 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Trending

Most Viewed

Loading...