PUP.Amigo

Analysis Report

General information

Family Name: PUP.Amigo
Signature status: Self Signed

Known Samples

MD5: 692731b3079ebbdbfca7ed5647599a08
SHA1: 5b84ff466f8339ae430c7a31da2b548dba6e2db2
SHA256: CF325A267F5C15A482B6541605D1DAB5684848ADF34D52473699F41E8AB231D0
File Size: 422.62 KB, 422616 bytes
MD5: 84c83a44f9797547ac5ec89eb86c8205
SHA1: 82e1db65bbec124618e623dfea83657aae6ae78d
SHA256: 48185404ADAC934EB3BCD685BC136186A707DF8E69F08352D30657566C97FC40
File Size: 401.64 KB, 401640 bytes
MD5: 3d489604ad99718b9d51b21edfa025cc
SHA1: ba2ce7b59a90259d69e9304c11165b3de487e5ee
SHA256: 487EAD5585F7F2873725597144A582C416C93606475AEC597DCD50BC30F5D83D
File Size: 422.62 KB, 422616 bytes
MD5: e775dd5fc63131b7ce757ea4b38f4016
SHA1: 6f9cf28482dac6ec03c840b3d92f69133cf9dd2b
SHA256: 69AAC7AACB86D597FD0959C120561024EEBC077DBA910957CB442D63045A5FAF
File Size: 352.49 KB, 352488 bytes
MD5: e6b4d99a5aad4945b36c25c6d6f1d8dd
SHA1: 0a4dad76f86072d1eeececc1d6bd971bec6247b5
SHA256: 11CDBA617C0C321E189E8056F9DDD239C571267161D60A5147E7FEE6F8B79213
File Size: 462.80 KB, 462800 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File has exports table
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name
  • Dilane Limited
  • Mail.Ru
Company Short Name Dilane Limited
File Description
  • Amigo@Mail.Ru
  • FreeU
  • Go! Browser
File Version
  • 56.1.2924.93
  • 2.0.0.377
  • 2.0.0.169
  • 2.0.0.89
Internal Name
  • Amigo Mail.Ru
  • chrome_watcher_dll
  • Go! Browser
Last Change 01989b478b88f29cc27177acab0b3c5d5c028eca
Legal Copyright
  • Copyright 2015
  • Copyright 2017
  • Copyright 2017 The Chromium Authors. All rights reserved.
Official Build 1
Original Filename
  • Amigo@Mail.Ru
  • chrome_watcher.dll
  • Go! Browser
Product Name
  • Amigo@Mail.Ru
  • FreeU
  • Go! Browser
Product Short Name FreeU
Product Version
  • 56.1.2924.93
  • 2.0.0.377
  • 2.0.0.169
  • 2.0.0.89

Digital Signatures

Signer Root Status
Dilane Limited Dilane Limited Self Signed

File Traits

  • HighEntropy
  • x86

Block Information

Total Blocks: 2,053
Potentially Malicious Blocks: 19
Whitelisted Blocks: 1,839
Unknown Blocks: 195

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 x 0 ? 0 0 0 0 0 0 ? ? 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 x 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? ? ? ? 0 x ? 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? 0 0 0 0 0 ? ? ? 0 ? 0 ? 0 ? ? 0 0 ? 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? ? ? ? 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 0 0 0 0 ? ? 0 ? 0 0 0 0 ? ? ? ? 0 ? ? 0 0 0 ? ? ? 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? ? 0 0 ? ? ? ? ? ? ? ? 0 0 0 0 0 0 ? ? ? ? ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 ? 0 0 0 0 0 0 0 0 ? 0 ? ? 0 0 ? 0 ? ? 0 ? 0 ? ? ? ? ? 0 ? ? ? 0 0 ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 ? ? ? 0 0 0 0 0 0 0 ? ? ? 0 0 0 ? 0 0 0 0 0 ? 0 0 ? 0 ? ? 0 0 0 0 ? 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? x ? x ? x 0 ? 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? 0 0 0 ? 0 0 0 ? 0 ? 0 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? ? ? ? ? ? ? ? ? 0 0 ? 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? ? 0 0 0 0 0 ? ? ? ? 0 0 0 0 0 0 x 0 ? 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 ? ? ? ? ? ? 0 0 0 0 0 x 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 0 ? 0 0 0 0 0 0 ? ? 0 0 0 0 0 ? ? ? 0 ? 0 ? 0 ? 0 0 ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 1 1 0 0 1 0 0 0 0 0 0 0 0 0 2 0 0 0 3 1 1 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 1 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 2 1 0 0 1 1 1 0 0 1 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
c:\users\user\appdata\local\temp\loader_ldir_2052_175\ba2ce7b59a90259d69e9304c11165b3de487e5ee_0000422616 Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\local\temp\loader_ldir_5752_22350\5b84ff466f8339ae430c7a31da2b548dba6e2db2_0000422616 Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144

Registry Modifications

Key::Value Data API Name
HKCU\software\mail.ru\go2installer::loaderguid {935EED24-B164-4053-A350-761218B86615} RegNtPreCreateKey
HKCU\software\mail.ru\amigoinstaller::loaderguid {F136E2C7-5EEC-4557-906D-52D70501CF13} RegNtPreCreateKey
HKCU\software\mail.ru\go2installer::loaderguid {BF26C704-199C-458E-AF2C-4B807D4C411C} RegNtPreCreateKey
HKCU\software\mail.ru\amigoinstaller::guid {430A2473-DDE7-4B7E-8828-F66842861DCA} RegNtPreCreateKey

Windows API Usage

Category API
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Network Wininet
  • HttpOpenRequest
  • HttpQueryInfo
  • HttpSendRequest
  • InternetConnect
  • InternetOpen
  • InternetOpenUrl
  • InternetSetOption
Network Winhttp
  • WinHttpOpen
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtQueryAttributesFile
Show More
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWriteFile
Anti Debug
  • NtQuerySystemInformation

Shell Command Execution

C:\Users\Egbjrure\AppData\Local\Temp\loader_ldir_5752_22350\5b84ff466f8339ae430c7a31da2b548dba6e2db2_0000422616 --wi=0 --import-settings=L --make-default=1 --attr=901406chsg --rfr=901406 --ext_params="old_mr1lad%3D5bd5a48e16ee8fb3-300-300-" --cp
C:\Users\Zvsmzruh\AppData\Local\Temp\loader_ldir_2052_175\ba2ce7b59a90259d69e9304c11165b3de487e5ee_0000422616 --wi=0 --import-settings=L --attr=901406ff --rfr=901406 --ext_params="old_mr1lad%3D5b7658eb291c4ec8-1000-1000-" --cp
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\0a4dad76f86072d1eeececc1d6bd971bec6247b5_0000462800.,LiQMAxHB

Trending

Most Viewed

Loading...