PUP.Amigo

Analysis Report

General information

Family Name: PUP.Amigo
Signature status: Modified signature

Known Samples

MD5: 692731b3079ebbdbfca7ed5647599a08
SHA1: 5b84ff466f8339ae430c7a31da2b548dba6e2db2
SHA256: CF325A267F5C15A482B6541605D1DAB5684848ADF34D52473699F41E8AB231D0
File Size: 422.62 KB, 422616 bytes
MD5: 84c83a44f9797547ac5ec89eb86c8205
SHA1: 82e1db65bbec124618e623dfea83657aae6ae78d
SHA256: 48185404ADAC934EB3BCD685BC136186A707DF8E69F08352D30657566C97FC40
File Size: 401.64 KB, 401640 bytes
MD5: 3d489604ad99718b9d51b21edfa025cc
SHA1: ba2ce7b59a90259d69e9304c11165b3de487e5ee
SHA256: 487EAD5585F7F2873725597144A582C416C93606475AEC597DCD50BC30F5D83D
File Size: 422.62 KB, 422616 bytes
MD5: e775dd5fc63131b7ce757ea4b38f4016
SHA1: 6f9cf28482dac6ec03c840b3d92f69133cf9dd2b
SHA256: 69AAC7AACB86D597FD0959C120561024EEBC077DBA910957CB442D63045A5FAF
File Size: 352.49 KB, 352488 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name Mail.Ru
File Description
  • Amigo@Mail.Ru
  • Go! Browser
File Version
  • 2.0.0.377
  • 2.0.0.169
  • 2.0.0.89
Internal Name
  • Amigo Mail.Ru
  • Go! Browser
Legal Copyright
  • Copyright 2015
  • Copyright 2017
Original Filename
  • Amigo@Mail.Ru
  • Go! Browser
Product Name
  • Amigo@Mail.Ru
  • Go! Browser
Product Version
  • 2.0.0.377
  • 2.0.0.169
  • 2.0.0.89

File Traits

  • HighEntropy
  • x86

Block Information

Total Blocks: 931
Potentially Malicious Blocks: 9
Whitelisted Blocks: 824
Unknown Blocks: 98

Visual Map

0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 ? ? ? ? ? ? 1 0 ? ? 1 ? ? ? ? ? 0 ? ? 0 ? ? ? 0 0 0 0 0 0 ? ? ? ? 1 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x ? ? ? ? x ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? 0 ? ? ? ? ? ? 1 ? ? ? ? ? ? ? 0 ? ? ? 0 ? ? x 0 1 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 x 0 0 0 0 ? 0 ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 1 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 1 0 0 x ? ? ? ? ? ? 0 x 0 0 0 0 0 ? ? ? 0 0 0 0 0 0 0 0 ? ? 1 ? ? ? ? ? ? ? 0 0 0 ? ? ? ? ? ? 0 x ? ? 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 1 0 0 0 2 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 1 0 0 1 0 0 0 0 0 0 1 0 0 0 0 1 1 0 0 0 0 0 1 0 3 1 1 1 1 1 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 1 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 3 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 1 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 2 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
c:\users\user\appdata\local\temp\loader_ldir_2052_175\ba2ce7b59a90259d69e9304c11165b3de487e5ee_0000422616 Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\local\temp\loader_ldir_5752_22350\5b84ff466f8339ae430c7a31da2b548dba6e2db2_0000422616 Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144

Registry Modifications

Key::Value Data API Name
HKCU\software\mail.ru\go2installer::loaderguid {935EED24-B164-4053-A350-761218B86615} RegNtPreCreateKey
HKCU\software\mail.ru\amigoinstaller::loaderguid {F136E2C7-5EEC-4557-906D-52D70501CF13} RegNtPreCreateKey
HKCU\software\mail.ru\go2installer::loaderguid {BF26C704-199C-458E-AF2C-4B807D4C411C} RegNtPreCreateKey
HKCU\software\mail.ru\amigoinstaller::guid {430A2473-DDE7-4B7E-8828-F66842861DCA} RegNtPreCreateKey

Windows API Usage

Category API
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Network Wininet
  • HttpOpenRequest
  • HttpQueryInfo
  • HttpSendRequest
  • InternetConnect
  • InternetOpen
  • InternetOpenUrl
  • InternetSetOption
Network Winhttp
  • WinHttpOpen

Shell Command Execution

C:\Users\Egbjrure\AppData\Local\Temp\loader_ldir_5752_22350\5b84ff466f8339ae430c7a31da2b548dba6e2db2_0000422616 --wi=0 --import-settings=L --make-default=1 --attr=901406chsg --rfr=901406 --ext_params="old_mr1lad%3D5bd5a48e16ee8fb3-300-300-" --cp
C:\Users\Zvsmzruh\AppData\Local\Temp\loader_ldir_2052_175\ba2ce7b59a90259d69e9304c11165b3de487e5ee_0000422616 --wi=0 --import-settings=L --attr=901406ff --rfr=901406 --ext_params="old_mr1lad%3D5b7658eb291c4ec8-1000-1000-" --cp

Trending

Most Viewed

Loading...