PUP.BadJoke.PI

Analysis Report

General information

Family Name: PUP.BadJoke.PI
Signature status: No Signature

Known Samples

MD5: a917d77d01c355f8d86d2925f793629e
SHA1: 8e06f16d4f099666714f1ee34a7a98129bda2615
SHA256: 0068141D4E450674B367482C32754B0EEA6D3A9CBA76B6BF54C59E5CF451F449
File Size: 641.51 KB, 641509 bytes
MD5: 9bf00aa3391bf42c3c75a87340cc5cca
SHA1: 204e8f9bc9ed0195e6477d18fbfdb1a6cae65419
SHA256: A27F345D8955814E1B772C50860458A6F6FC0B9E22D8D9566301D00E50FB7EDD
File Size: 4.27 MB, 4267653 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Nenad Hrg (SoftwareOK.de)
Company Name Nenad Hrg (SoftwareOK.com)
File Description
  • TheAeroClock
  • Twisted Lands: Origin
File Version
  • 3, 8, 1, 0
  • 1, 0, 0, 1
Internal Name
  • TheAeroClock
  • Twisted Lands: Origin
Legal Copyright
  • Copyright (C) 2012
  • Copyright © 2011-2015
Original Filename
  • TheAeroClock.exe
  • Twisted Lands: Origin
Product Name
  • TheAeroClock SoftwareOK.com
  • Twisted Lands: Origin
Product Version
  • 3, 8, 1, 0
  • 1, 0, 0, 0
Thin App Build Date Time
  • 20150816 131735
  • 20161008 211209
Thin App License
  • PORTAL PORTABLES BRASIL
  • VMware ThinApp
Thin App Version
  • 5.1.1-2722044

File Traits

  • big overlay
  • ntdll
  • WriteProcessMemory
  • x86

Block Information

Total Blocks: 534
Potentially Malicious Blocks: 183
Whitelisted Blocks: 351
Unknown Blocks: 0

Visual Map

x x x x x 0 x x x x x x x x x x x 0 x x x 0 0 x 0 0 0 x x x x x x x x x x x x x x 0 x x x 0 x x 0 x 0 x x x x x x x x x x x x x x x x 0 x x x x x x 0 x x x x x 0 x x x x x x 0 x x 0 x x x 0 x x x 0 x 0 x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x 0 x x x x x x x x 0 0 x x x x 0 0 x x x x x x x 0 x x x x x 0 x x x x 0 x x 0 x x x x x 0 0 0 0 0 x x x 0 0 0 0 x x x x x x x x x x x x x x x x x x x x x x x x 0 x x 0 x 0 0 0 x x x x x 0 x x x 0 x 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 2 2 0 0 1 1 0 0 0 0 1 1 0 0 1 0 0 0 0 0 2 0 0 0 0 0 1 0 0 0 0 0 0 0 0 1 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 1 2 3 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 1 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 2 0 0 1 0 0 0 1 1 1 0 1 1 1 0 0 1 1 0 1 0 0 0 0 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 1 1 0 0 1 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
c:\users\user\downloads\theaeroclock\registry.rw.tvr Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\downloads\theaeroclock\registry.rw.tvr.lck Synchronize,Write Data
c:\users\user\downloads\theaeroclock\registry.rw.tvr.lck.desktop-dlos3m3.ffffffff.1894 Generic Write,Read Attributes
c:\users\user\downloads\theaeroclock\registry.rw.tvr.transact Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\downloads\theaeroclock\registry.rw.tvr.transact Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\downloads\theaeroclock\registry.tlog Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\downloads\theaeroclock\registry.tlog.cache Generic Read,Write Data,Write Attributes,Write extended,Append data

Windows API Usage

Category API
Anti Debug
  • NtQuerySystemInformation

Trending

Most Viewed

Loading...