PUP.Distromatic

Analysis Report

General information

Family Name: PUP.Distromatic
Signature status: No Signature

Known Samples

MD5: 818bb318e788527ff858739142c711be
SHA1: b40e4b581b4d50a9efdf326daa98a76d5db0ff09
SHA256: D20EF41B838C654371F6DE591EE31DC54AC432C720A704B6414AAF43FA86C676
File Size: 641.40 KB, 641402 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
File Description Amazon Browser Bar
File Version 1.0
I W Build Date 20130904T144534
I W Keyword distro-amzn-opencandy-rs
I W Version 2.3.7
Product Name Amazon Browser Bar
Product Version 1.0

Files Modified

File Attributes
c:\users\user\appdata\local\temp\nsf9458.tmp\stack.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsf9458.tmp\system.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsf9458.tmp\zplugins.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsp92c1.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete
c:\users\user\appdata\local\temp\nsz93e9.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete
c:\users\user\appdata\local\temp\~nsu.tmp\au_.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144

Registry Modifications

Key::Value Data API Name
HKLM\system\controlset001\control\session manager::pendingfilerenameoperations \??\C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.205.9\??\C:\Windows\SystemTemp\ff868642-5eca-44d0-82c1-d6b43ea019a7.tmp\ RegNtPreCreateKey
HKLM\system\controlset001\control\session manager::pendingfilerenameoperations \??\C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.205.9\??\C:\Windows\SystemTemp\ff868642-5eca-44d0-82c1-d6b43ea019a7.tmp\ RegNtPreCreateKey

Windows API Usage

Category API
Process Shell Execute
  • CreateProcess

Shell Command Execution

"C:\Users\Pghfuekt\AppData\Local\Temp\~nsu.tmp\Au_.exe" _?=c:\users\user\downloads\

Trending

Most Viewed

Loading...