PUP.DialupPass.A

Analysis Report

General information

Family Name: PUP.DialupPass.A
Packers: UPX
Signature status: No Signature

Known Samples

MD5: 0481d2e281d173aee1ad883b1bc0c255
SHA1: e1c7b220e5b3d916bca4e8f58134d209cd68a4aa
SHA256: 572F3DEC8FBE7CA65B3335020F1A4F7BA715557460FBACC7C7338247D36BE3DF
File Size: 8.31 MB, 8312320 bytes
MD5: 0771acdc653eac4383109dea220ad25c
SHA1: 0640d2e845ef8619f48b6a4cec2234cfa915faec
SHA256: 53D18AC64A1F7607FEB8B3A4495DA6A4543CA25BC2A964F2E86F0C7377A502F3
File Size: 237.80 KB, 237800 bytes
MD5: f89c093212db6bce05d6767626407f03
SHA1: 23a429e86fe99f73de394f0d56de1a2c74e47c3e
SHA256: 298785131AC5D295BBC2BAFF9F7DDFD1162A0CEE1176FF7168F7A97A471B5634
File Size: 4.45 MB, 4452760 bytes
MD5: 404db851c8bd23df4898c76d87ee588e
SHA1: 0b567e165db957fa4aeed47971efb60358c6b20e
SHA256: 1E92B5E313F6DB5946F98F8B005FAB77483A162B7BD9362CCBC9FFE141811B08
File Size: 745.19 KB, 745186 bytes
MD5: 3f51b915918b6610850bcdcd1d09d437
SHA1: fa377e2ba8903962766a335584be44e9ed9f6eb1
SHA256: C590D921CB884A36CB71893B181DAB45F0FAF7B73FE1D91101E971C237508D81
File Size: 239.67 KB, 239674 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has been packed
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments
  • PE2.0 Cd open
  • Utilitaire de conversion d'image en Splash Screen TomTom avec Iview32.exe
Company Name AutoIt Team
Compilation Date 18/06/2007
Compilation Heure 02:34:45
Compiled Script AutoIt v3 Script : 3, 2, 4, 9
Créer Par Tlem
Email tlem@tuxolem.net
Entreprise Tuxolem Software
File Description
  • AutoIt v3 Setup
  • Créateur de Splash Screen TomTom
  • FastStone Capture三哥汉化分享
  • Simple CDROM open sw
File Version
  • 9.1.0.0
  • 3.2.4.9
  • 3, 2, 4, 9
  • 1.1.0.0
  • 1.0.0.0
Legal Copyright
  • (c)1999-2007 Jonathan Bennett & AutoIt Team
  • Copyright (C) 2003 - 2007 Tuxolem Software
  • Copyright (C) 2019 by FastStone Soft
Nom Interne TomTom Splash Screen Creator
Product Version 3.3.9.4
Version Du Compilateur AutoIt v3.2.4.9

Digital Signatures

Signer Root Status
Belgacom GlobalSign Root CA Root Not Trusted
Jonathan Bennett GlobalSign Root CA Root Not Trusted

File Traits

  • Autoit
  • big overlay
  • HighEntropy
  • packed
  • WriteProcessMemory
  • x86

Block Information

Total Blocks: 1,505
Potentially Malicious Blocks: 785
Whitelisted Blocks: 717
Unknown Blocks: 3

Visual Map

x x 0 x x x 0 0 x 0 0 x x 0 x 0 x x x x x x x x x x x x x x x x x x x 0 x x 0 x x x x x 0 0 x x 0 x x x 0 x x x x x x x x x x 0 0 x 0 x x x x x x x 0 0 x x 0 x 0 x x x x x x x x x x x x x 0 x x x x 0 x x x x x x x 0 x x x x x x x x x x x x x x x x x 0 0 x x x x x x x 0 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x x x x x x x x x x 0 x x x x x x x x 0 x x 0 x x x x x x x x x x x 0 0 0 0 0 0 0 x 0 0 0 x x x 0 x x x x 0 0 x x x x 0 x 0 0 0 0 x x x x 0 x x x x x x x x x 0 x x x x x x x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x x x 0 x x 0 0 x 0 x 0 x x 0 0 0 0 0 0 x x x x x x x x x 0 0 x x x x x 0 x x x x x 0 x 0 x x 0 x x x x 0 0 0 x x 0 0 0 x x x x x x x x x 0 x x 0 0 x x 0 x x x 0 0 x x x 0 x 0 x x x x x x x x x x x x x x 0 0 x x x x x x 0 x 0 x x 0 x 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x 0 x 0 x x x x x x x x x x x x x 0 x x x x x x x 0 x x x x 0 x x x x x x x x x x x x x x x x x 0 x x x 0 x 0 x x x 0 0 x x 0 0 x x x x x x x 0 x x x x 0 0 x x 0 x x 0 0 x x x 0 0 0 x x x 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x x 0 0 x 0 x x x 0 x 0 0 x 0 0 x 0 x 0 0 x 0 0 0 0 x x x x 0 0 x x x 0 x x 0 x x x x x x x x x x x x x x x x x 0 0 x x x x x x 0 0 0 0 x 0 0 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 0 0 0 0 0 x x x x x x x x x x 0 x x x x x x x x x x x x x x x x x x 0 x x 0 x 0 0 x 0 0 0 0 0 x x x x x x x x x x x x x x x x x x x 0 0 x x 0 x x 0 x x x x 0 x x x x x x x x x x x x x x x x x x 0 x 0 x x x x x 0 x x x 0 x x x x 0 x x x x x x x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x x x x x x x x x x x x x x 0 x x x x x x x x x x x 0 x x x x x x x x x x x 0 x x x x x x x x x x x 0 x x x x x x x x 0 x x x x x x x x 0 x x 0 x 0 0 0 0 x 0 x 0 x x x x 0 x x x x x x x x x x x x 0 x x x x x x x x x x x x x x x x x x x 0 x x 0 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 0 0 x x 0 x 0 0 0 x x 0 x x x x x 0 0 0 0 x x 0 0 x 0 x x x 0 x 0 x x x 0 x 0 0 0 0 x x 0 0 x x 0 0 x 0 0 0 0 0 0 0 x x x 0 0 0 x 0 0 x x 0 x x 0 x 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 1 0 0 0 1 0 0 0 1 0 0 0 0 1 0 1 0 1 0 0 1 1 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 1 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 ? 0 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Autoit
  • BadJoke.FH
  • DialupPass.A
  • Sohanad.B

Files Modified

File Attributes
c:\users\user\appdata\local\temp\aut363e.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\aut364f.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\aut37a8.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\aut3816.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\aut3836.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\aut3857.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\aut3896.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\aut38d6.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\aut3a1f.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\aut3a7e.tmp Generic Write,Read Attributes
Show More
c:\users\user\appdata\local\temp\aut579e.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\autad5f.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\eject.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\i_view32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\local\temp\i_view32.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsca8cf.tmp\installoptions.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsca8cf.tmp\iodefaultopen.ini Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\nsca8cf.tmp\iodefaultopen.ini Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsca8cf.tmp\iopreviousversion.ini Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\nsca8cf.tmp\iopreviousversion.ini Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsca8cf.tmp\iospecial.ini Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\nsca8cf.tmp\iospecial.ini Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsca8cf.tmp\modern-header.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsca8cf.tmp\modern-wizard.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsca8cf.tmp\userinfo.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsna8bf.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete
c:\users\user\appdata\local\temp\portable faststone capture rus Synchronize,Write Attributes
c:\users\user\appdata\local\temp\portable faststone capture rus\fsc.db Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\portable faststone capture rus\fsc.db Generic Write,Read Attributes
c:\users\user\appdata\local\temp\portable faststone capture rus\fscapture.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\portable faststone capture rus\fscapture.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\portable faststone capture rus\fscapture.rus Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\portable faststone capture rus\fscapture.rus Generic Write,Read Attributes
c:\users\user\appdata\local\temp\portable faststone capture rus\fscapturehelp.chm Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\local\temp\portable faststone capture rus\fscapturehelp.chm Generic Write,Read Attributes
c:\users\user\appdata\local\temp\portable faststone capture rus\fscapturehelp.chm.bak Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\local\temp\portable faststone capture rus\fscapturehelp.chm.bak Generic Write,Read Attributes
c:\users\user\appdata\local\temp\portable faststone capture rus\fscrosshair.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\portable faststone capture rus\fscrosshair.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\portable faststone capture rus\fsfocus.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\portable faststone capture rus\fsfocus.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\portable faststone capture rus\fsrecorder.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\portable faststone capture rus\fsrecorder.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\portable faststone capture rus\fsrecorder.rus Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\portable faststone capture rus\fsrecorder.rus Generic Write,Read Attributes
c:\users\user\appdata\local\temp\portable faststone capture rus\portable.db Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\portable faststone capture rus\portable.db Generic Write,Read Attributes
c:\users\user\downloads\0640d2e845ef8619f48b6a4cec2234cfa915faec_0000237800.manifest Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\downloads\0640d2e845ef8619f48b6a4cec2234cfa915faec_0000237800.manifest Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKLM\software\wow6432node\supportsoft\providerlist\belgacom::ldrrestart manifest RegNtPreCreateKey

Windows API Usage

Category API
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserName
  • GetUserObjectInformation
Process Shell Execute
  • CreateProcess
Process Manipulation Evasion
  • NtUnmapViewOfSection
Other Suspicious
  • SetWindowsHookEx
Keyboard Access
  • GetAsyncKeyState
  • GetKeyState

Shell Command Execution

C:\Users\Vljeakzb\AppData\Local\Temp\Portable FastStone Capture RUS\FSCapture.exe
C:\Users\user\downloads\0640d2e845ef8619f48b6a4cec2234cfa915faec_0000237800

Trending

Most Viewed

Loading...