PUP.Cain.A

Analysis Report

General information

Family Name: PUP.Cain.A
Signature status: No Signature

Known Samples

MD5: aabb0434bbc1c5da1ca1b1f0a2b34fe5
SHA1: bd3b1b957248dc1bb82eb5de19fdd0ab9cf94af6
SHA256: DF435B9185E6B4C1DDFF9A4835A1C61623D9E9ABEB56B0623F75716601DBC088
File Size: 2.27 MB, 2273892 bytes
MD5: 16f945b719635532d1f3c8880332c837
SHA1: 5885e47927da6831377b8df56502cde8ea00895f
SHA256: 95F46B1B458D40AAA6A75EB376AE9A2EE06F367C0F16DB7A438B81BD8CC44177
File Size: 5.43 MB, 5434062 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have security information
  • File has exports table
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

File Traits

  • big overlay
  • No Version Info
  • x86

Files Modified

File Attributes
\device\namedpipe\gmdasllogger Generic Write,Read Attributes
c:\users\user\appdata\local\temp\gl_24c0.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\gl_bdb7.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\glf28bb.tmp Synchronize,Write Attributes
c:\users\user\appdata\local\temp\glf28bb.tmp Synchronize,Write Data
c:\users\user\appdata\local\temp\glf28cb.tmp Synchronize,Write Attributes
c:\users\user\appdata\local\temp\glf28cb.tmp Synchronize,Write Data
c:\users\user\appdata\local\temp\glfc1b2.tmp Synchronize,Write Attributes
c:\users\user\appdata\local\temp\glfc1b2.tmp Synchronize,Write Data
c:\users\user\appdata\local\temp\glfc1c3.tmp Synchronize,Write Attributes
Show More
c:\users\user\appdata\local\temp\glfc1c3.tmp Synchronize,Write Data
c:\users\user\appdata\local\temp\glg28ba.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\glgc1b1.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~glh0002.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~glh0003.tmp Generic Write,Read Attributes
c:\windows\syswow64\glbsinst.%$d Generic Write,Read Attributes
c:\windows\~glc0000.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\~glh0000.tmp Generic Write,Read Attributes
c:\windows\~glh0001.tmp Generic Write,Read Attributes

Windows API Usage

Category API
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation

Trending

Most Viewed

Loading...