PUP.DllInject.PA

The detection of PUP.DllInject.PA on your system indicates the presence of a potentially unwanted program (PUP) that may be injecting malicious DLLs into your system. This type of threat can compromise your system's security and potentially lead to further malware infections. It is essential to understand the nature of this threat and take immediate action to remove it from your system.

What Is PUP.DllInject.PA?

PUP.DllInject.PA is a type of potentially unwanted program that is designed to inject malicious DLLs (Dynamic Link Libraries) into your system. These DLLs can be used to perform various malicious activities, such as stealing sensitive information, hijacking system resources, or installing additional malware. PUPs like PUP.DllInject.PA are often bundled with free software or downloaded from untrusted sources, making them a common threat to many computer users.

How PUP.DllInject.PA Operates

PUP.DllInject.PA operates by injecting malicious DLLs into your system, which can then interact with other system components to perform malicious activities. These DLLs can be used to modify system settings, steal sensitive information, or install additional malware. The PUP may also use various techniques to evade detection, such as code obfuscation or anti-debugging techniques. Once installed, PUP.DllInject.PA can be difficult to remove, making it essential to use specialized tools and techniques to eliminate the threat.

Symptoms of Infection

The symptoms of a PUP.DllInject.PA infection can vary, but common indicators include slow system performance, unexpected crashes, and unusual system behavior. You may also notice unfamiliar programs or icons on your system, or receive unexpected pop-ups or alerts. In some cases, the PUP may also hijack your browser or other system components, leading to further malicious activity.

  • Slow system performance or crashes
  • Unfamiliar programs or icons on your system
  • Unexpected pop-ups or alerts
  • Browser hijacking or unusual browser behavior

How to Remove PUP.DllInject.PA

  1. Boot your system in Safe Mode with Networking to prevent the PUP from loading
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and remove the PUP
  3. Uninstall any suspicious programs or applications that may be related to the PUP
  4. Reset your browser settings to their default values, including Chrome, Firefox, and Edge
  5. Reboot your system and perform a follow-up scan to ensure the PUP has been completely removed

Conclusion

Removing PUP.DllInject.PA from your system requires careful attention to detail and the use of specialized tools and techniques. By following the steps outlined above, you can help ensure the complete removal of the PUP and prevent further malicious activity. It is also essential to practice safe computing habits, such as avoiding untrusted software downloads and using reputable anti-malware tools, to prevent similar infections in the future. Remember to always stay vigilant and take immediate action if you suspect your system has been compromised by a potentially unwanted program like PUP.DllInject.PA.

Analysis Report

General information

Family Name: PUP.DllInject.PA
Signature status: No Signature

Known Samples

MD5: c0631c5d9681967bc9e1e1034b4250b7
SHA1: 940846d9df8d26979add17648fd6229eb1816fd7
SHA256: 1CDF197643E6B4D1D3FFA4C2AD5166849375191EB338378F2CD7C4D8F0793F8D
File Size: 1.63 MB, 1634304 bytes
MD5: da1ac4581197cdd0df900e0bb8fb7b1b
SHA1: 1d3f32b018376d51a6e95ba70eb641185b0683d6
SHA256: A8ECA46F20CFC5E00208ED7A4261FAA03543924F2D433BEBB67681D31AD9FDD5
File Size: 310.78 KB, 310784 bytes
MD5: a6d36605928d8c58c787fbb76a668aef
SHA1: 5b7339e9e0b0798e16c82cea724bfa7a0af350c1
SHA256: B3D4427FA3C8F0795A8EFFFBC069EC964521E7D51B92DDE4D275DF66BFBDDCB9
File Size: 1.66 MB, 1658880 bytes
MD5: 29dece1cfcdf53d3634f5807b6855ab6
SHA1: 2e2326b08888e8cd7990f34ebc7c49fbda7a9da2
SHA256: E4857708D27274AF4DB3502ED6E82CC146D129EDE58B656CF214B65EBC366DCF
File Size: 442.88 KB, 442880 bytes
MD5: 6d881d61130342a1099f691906c78758
SHA1: 28e33bc1084315229f0b887e51fca2455269b33b
SHA256: 172969D0E885169515AD44D99636AE7BC4F00D339E6A31C33C4E68E0979A30DC
File Size: 1.57 MB, 1570816 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Comments
  • LunaHost v3.10
  • LunaTranslator v7.11
  • LunaTranslator v7.23
  • LunaTranslator v10.5
File Description
  • LunaHost
  • LunaTranslator
File Version
  • 10.5.0.1
  • 7.23.1.0
  • 7.11.4.0
  • 3.10.0.0
Internal Name
  • LunaHost
  • LunaTranslator
Legal Copyright
  • HIllya51 (C) 2024
  • HIllya51 (C) 2025
Original Filename
  • LunaHost
  • LunaTranslator
Product Name
  • LunaHost
  • LunaTranslator
Product Version
  • 10.5.0.1
  • 7.23.1.0
  • 7.11.4.0
  • 3.10.0.0

File Traits

  • dll
  • HighEntropy
  • No Version Info
  • VirtualQueryEx
  • WriteProcessMemory
  • x86

Block Information

Total Blocks: 4,707
Potentially Malicious Blocks: 348
Whitelisted Blocks: 2,880
Unknown Blocks: 1,479

Visual Map

0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 ? x x 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 ? ? x ? ? 0 ? ? 0 0 ? ? ? x ? ? x ? x x ? x x 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 ? ? ? 0 0 x 0 0 ? 0 0 x ? ? 0 0 ? 0 0 ? 0 0 0 0 ? ? ? ? ? ? 0 ? x x 0 ? 0 ? 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 ? ? 0 0 0 0 0 ? ? 0 x 0 0 ? 0 ? ? ? ? ? ? 0 ? ? ? ? 0 0 ? 0 0 0 ? ? ? ? ? 0 ? 0 0 0 0 0 x ? x ? ? x 0 0 ? ? ? ? ? 0 0 ? ? ? ? ? ? 0 0 0 0 0 0 0 0 ? ? ? ? ? 0 0 ? ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? x ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? 0 ? ? ? ? ? 0 ? 0 ? ? 0 ? ? ? ? ? ? ? 0 ? 0 0 0 0 0 0 ? ? ? 0 0 ? ? 0 ? 0 ? 0 ? ? ? ? ? 0 ? 0 ? ? ? 0 ? ? ? ? ? 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? x ? x ? ? ? ? ? ? ? ? ? 0 ? ? ? ? 0 ? ? ? ? ? ? ? ? ? 0 ? 0 0 ? ? 0 ? 0 0 ? ? ? ? ? 0 ? ? 0 0 ? 0 ? ? ? x x 0 ? ? ? ? ? ? 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? 0 0 0 0 0 ? 0 ? ? 0 x x 0 0 0 x x x 0 0 x x x 0 ? 0 ? ? ? 0 0 0 ? 0 ? ? ? 0 0 ? x ? ? 0 ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 ? ? 0 ? ? ? ? x ? ? ? ? ? 0 ? 0 0 ? 0 0 ? ? ? ? ? ? ? ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 ? x ? ? x 0 x 0 ? ? ? 0 x x 0 0 0 0 0 0 0 0 ? 0 0 ? ? 0 0 0 0 ? ? ? 0 0 0 ? 0 ? 0 ? ? ? ? x ? ? 0 ? ? 0 0 ? ? ? ? ? ? 0 0 ? ? 0 0 x ? 0 0 0 ? ? 0 0 ? 0 ? 0 ? ? ? ? ? x ? ? ? ? 0 ? x x x x ? ? x x ? 0 ? ? ? 0 0 ? ? 0 0 ? x 0 ? 0 0 0 x x ? ? ? ? ? ? 0 ? ? 0 0 ? ? ? ? 0 0 ? ? ? ? 0 ? ? 0 ? 0 ? ? 0 0 ? ? ? 0 0 0 ? ? 0 0 ? ? ? ? ? ? ? ? 0 0 ? ? ? ? 0 ? ? ? ? ? ? 0 ? ? ? x 0 0 0 ? 0 0 ? ? ? ? ? 0 ? ? ? ? ? 0 x ? ? ? x ? ? 0 0 0 ? ? ? ? ? 0 ? ? ? ? ? ? ? 0 ? 0 ? ? ? ? ? ? 0 0 x ? ? x ? ? ? 0 ? ? ? ? 0 0 0 0 ? ? ? x ? ? ? x 0 0 0 ? ? 0 ? ? ? 0 x ? ? 0 x ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 ? 0 ? 0 ? x x x x x x ? ? x x x x ? ? ? 0 ? ? ? ? ? ? ? ? 0 ? ? x ? ? ? ? 0 0 ? x 0 ? x ? ? x ? 0 ? ? ? ? ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? 0 ? ? x ? ? x x 0 0 0 x x x 0 0 x ? ? ? 0 ? ? ? ? ? x ? ? 0 ? ? ? ? ? ? ? x x ? x ? x x x 0 x x x x ? 0 0 ? ? 0 ? ? ? x ? 0 0 ? ? ? ? ? x 0 0 x 0 ? ? ? ? ? 0 ? ? 0 x x ? ? ? ? ? ? ? ? ? ? x 0 0 ? 0 0 ? ? ? 0 ? ? ? ? ? ? 0 ? 0 ? ? ? ? ? ? 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? 0 0 ? 0 ? ? ? ? 0 x ? 0 ? ? ? ? ? 0 0 ? 0 x ? 0 0 ? x ? ? ? ? 0 0 ? ? 0 0 0 ? ? ? ? ? ? 0 ? ? 0 ? 0 0 ? ? 0 0 ? 0 0 0 ? ? ? ? ? ? ? ? x x 0 x ? ? ? ? 0 ? ? ? ? ? ? ? ? ? 0 0 ? ? ? ? ? ? 0 ? ? ? 0 ? ? ? ? ? ? 0 ? ? ? ? x ? ? ? ? 0 0 ? ? x ? ? ? 0 x 0 0 ? 0 0 ? ? ? x ? 0 ? ? ? x 0 0 0 ? 0 ? ? 0 0 0 0 ? 0 ? ? ? x ? ? ? ? ? ? ? ? ? 0 ? ? ? 0 ? ? ? ? ? ? ? ? 0 0 ? ? ? ? ? 0 ? ? ? ? 0 ? ? 0 ? 0 ? ? ? ? ? ? x x 0 ? ? ? ? ? ? ? ? ? ? 0 ? ? ? 0 ? ? ? ? ? ? 0 ? ? ? 0 0 0 ? ? ? x ? ? ? ? ? x 0 0 ? ? ? ? ? 0 ? ? 0 0 ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? 0 ? 0 ? ? ? ? ? 0 ? ? x ? ? ? 0 x ? ? 0 0 ? x ? ? ? ? ? x ? ? ? ? ? ? ? ? 0 ? ? ? ? 0 x ? 0 x ? 0 x ? ? ? ? ? ? 0 0 ? ? 0 0 ? ? ? ? ? ? ? 0 ? ? ? ? ? 0 0 x ? ? ? ? ? ? ? ? ? ? x x ? 0 0 0 ? x x x ? x ? ? 0 ? ? ? 0 ? ? 0 ? ? ? 0 0 0 ? 0 0 ? 0 ? 0 ? 0 0 ? ? 0 x 0 0 0 ? ? ? ? 0 ? x ? ? 0 ? ? ? ? 0 ? 0 ? 0 ? ? x ? ? ? 0 ? ? ? 0 ? 0 ? ? x ? ? ? ? x ? ? ? 0 ? ? ? 0 ? ? ? ? ? ? 0 ? 0 ? 0 0 ? ? ? x ? ? x ? ? 0 ? 0 ? ? ? ? ? ? ? 0 ? 0 ? ? 0 ? ? 0 0 ? ? 0 ? x ? ? 0 ? 0 ? ? ? ? ? 0 ? 0 ? 0 ? ? x ? ? x ? ? 0 ? ? ? ? 0 ? ? ? 0 ? ? ? x ? ? 0 ? ? ? ? ? 0 ? ? 0 ? ? 0 ? ? x ? ? 0 ? 0 ? ? ? 0 ? x ? ? ? x ? ? ? x ? ? x ? ? x ? ? 0 ? 0 ? ? x ? ? ? ? 0 ? 0 ? ? 0 ? ? ? 0 ? ? ? ? 0 ? 0 ? 0 ? ? 0 ? ? ? x ? ? ? 0 ? ? 0 ? x ? ? 0 ? ? ? 0 ? x ? ? x ? ? ? 0 ? 0 ? x ? ? 0 ? ? ? ? 0 ? ? ? ? 0 ? ? ? ? ? ? x ? ? x ? ? x ? ? ? ? x ? ? 0 ? 0 ? 0 ? ? 0 ? 0 ? 0 ? ? 0 ? 0 ? ? ? 0 ? ? ? ? 0 ? 0 ? 0 ? ? 0 ? x ? ? 0 ? ? ? ? ? 0 ? ? 0 ? ? 0 ? 0 ? 0 ? x ? ? x ? ? ? 0 ? x ? ? x ? ? 0 ? ? 0 ? ? ? ? 0 ? ? ? x ? 0 ? ? 0 ? ? 0 ? ? ? ? ? 0 ? 0 ? ? ? ? x x ? ? 0 ? ? x ? ? ? ? ? 0 ? ? ? x ? ? 0 ? ? ? ? ? 0 ? ? 0 x x ? ? x ? 0 x ? x ? x x x x ? x ? x ? ? x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Kryptik.VCKV

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtProtectVirtualMemory
Show More
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetThreadState
Process Shell Execute
  • CreateProcess
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
User Data Access
  • GetUserObjectInformation
Process Manipulation Evasion
  • NtUnmapViewOfSection

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\940846d9df8d26979add17648fd6229eb1816fd7_0001634304.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\1d3f32b018376d51a6e95ba70eb641185b0683d6_0000310784.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\5b7339e9e0b0798e16c82cea724bfa7a0af350c1_0001658880.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\28e33bc1084315229f0b887e51fca2455269b33b_0001570816.,LiQMAxHB

Related Posts

Trending

Most Viewed

Loading...