PUP.Bat2Exe.D

Analysis Report

General information

Family Name: PUP.Bat2Exe.D
Signature status: No Signature

Known Samples

MD5: a152e1fb1d58fc77fa3975016dc510a9
SHA1: 82820c1458af93019e83228220899c081085a2ad
SHA256: 836EF54253CC2340C7A457FA7A3BEFA89B3CB5EF19D13FB181A266C8B54A94F1
File Size: 128.39 KB, 128393 bytes
MD5: f46025a5bc13859ab8f444fda4c6471c
SHA1: a386bccfaef450bcc14b7c12d9a9a3def404f14b
SHA256: BD2E810760A41A5F95FD50E94C88FB77919E25352D1C28E00C326E486138BD68
File Size: 198.49 KB, 198485 bytes
MD5: aa59a99476bf427b808db64b2afabc2b
SHA1: 51450661f9e7d36ef7f6867446509d817380c9a6
SHA256: 316836F7B44779BE2208806AC2060BEDC945C243BCE4C03FF5D59B7EA85227EB
File Size: 69.81 KB, 69805 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name
  • UniversitÚ Grenoble Alpes
  • Your Company
File Description
  • Loic LEFORESTIER
  • Product Description
File Version
  • 24.11.22.0
  • 1.0.0.0
Legal Copyright Copyright Info
Product Name
  • MDT Software Install
  • Product Name
Product Version
  • 24.11.22.0
  • 1.0.0.0

File Traits

  • Installer Manifest
  • Installer Version
  • No Version Info
  • x86

Block Information

Total Blocks: 163
Potentially Malicious Blocks: 3
Whitelisted Blocks: 160
Unknown Blocks: 0

Visual Map

0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
c:\users\user\appdata\local\temp\ytmp\t25782ers\user\downloads\.bat Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ytmp\t25782ers\user\downloads\.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ytmp\t30484ers\user\downloads\.bat Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ytmp\t30484ers\user\downloads\.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ytmp\t31032ers\user\downloads\.bat Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ytmp\t31032ers\user\downloads\.exe Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKCU\local settings\muicache\1b\52c64b7e::@c:\windows\system32\ndfapi.dll,-40001 Windows Network Diagnostics RegNtPreCreateKey

Windows API Usage

Category API
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation

Trending

Most Viewed

Loading...