PUP.DotSetupIo

Analysis Report

General information

Family Name: PUP.DotSetupIo
Signature status: Root Not Trusted

Known Samples

MD5: df6ab261699e3728ca62666a684531a7
SHA1: 5c2b9b9124dc4b8c8d561e18f87e3a37d2fbf0a0
SHA256: DF845C2DFC62B727846A61806308A78F1C93C47E272E44D95BDF55806CD29F4D
File Size: 316.41 KB, 316408 bytes
MD5: 0a1d9adb2c415ad52f66a77f210e33f0
SHA1: f8e8813fb218ed652f7e554584dadd30ef034ed9
SHA256: A209BF4CED1EE999EBF1E55558E984FEF4C06F6DFCACEDAE4219DDBDAC351166
File Size: 300.06 KB, 300056 bytes
MD5: 86961c013b521f5795cc861626244156
SHA1: 6f01e7ebacbcf1630dc06523273b3da94dfb2b65
SHA256: 66D71566DFCA25549BA849C627EB0FEB8693C5CA0D095F9B3963A092EA559A68
File Size: 316.41 KB, 316408 bytes
MD5: c35622ba936f78ac50db978118eef2d8
SHA1: 0246c4234093c5a675a587da1a357de11be25111
SHA256: ED6950049C589EB0F4B04C3F1F5AD6C64688A7D134FBBA7D4DFEA4AF0D17F438
File Size: 316.41 KB, 316408 bytes
MD5: 1a52a2b0162e506c9bcbd26389f03a8b
SHA1: 53449fc3b38e1e63b1d1e8e19197b7f8fcec77f5
SHA256: F7A3F3E71D47E9EA515E4FC03510267AE9596F761D74F395A57F51E9082CEC06
File Size: 228.54 KB, 228536 bytes
Show More
MD5: 28b274163b08ce454b4fe7c5f066002d
SHA1: d62d711f014313b80812a2cb638dd10b469d38c5
SHA256: 8ED3888F8180D687C345F5984EA624B617B5F56739CFD176D38A8B8E750B6565
File Size: 316.41 KB, 316408 bytes
MD5: a1ed533099f199731bbead71cf2d71fd
SHA1: b401a53ed164d990713c14a8492e786f016dcb6d
SHA256: 1C364EADACA754254FAC676BC3F30DEA77E66E26CA1EE3F11D7C10010D894D33
File Size: 273.91 KB, 273912 bytes
MD5: a46a5db98c756737d851f339aedc4015
SHA1: baf643bc3ddcffc29945856ff531f29bae66e3ac
SHA256: BBA01ABC344F5C9B7C8113D38CFCABADE919D0482BAEFA0EC384FB8D281C84C0
File Size: 273.91 KB, 273912 bytes
MD5: a59d014ecd34923dad8c2173631b04a9
SHA1: 7583baf0d1bdad6f3c8b3d0a0f75a8ecf7a02810
SHA256: EC3FAA404A969BAA547B56B14131A3602B2DA31E3A4BDE7832F1CF9ACEE35790
File Size: 300.06 KB, 300056 bytes
MD5: 7bf5aad1d5776c03d47df69e2c11bac3
SHA1: d8caec4a69839dbd1f35399d2e0e848aa6636aad
SHA256: 8B49D3E48392601B1BEE4A088145F8CEEB182EE4FEE1B5A8BEB2217D746BFC50
File Size: 300.06 KB, 300056 bytes
MD5: 82613194f0bfc562c28ba537bc2f6591
SHA1: b2876ab53c143494829c744ff4620433834a13e1
SHA256: 4BD0D3ADE9640951911D84FDBA5ADE07113B8C121E9470F6FF96C42BAE7C5577
File Size: 316.41 KB, 316408 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File has exports table
  • File is .NET application
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Assembly Version
  • 4.0.1.1
  • 4.0.1.0
  • 1.92.3.8643
  • 0.0.0.0
Comments
  • DotSetupSDK Installer
  • MD_Utils Helper
  • Microvirt Installer
File Description
  • DotSetupSDK Installer
  • Microvirt Installer
  • Utils_MDS
File Version
  • 4.0.1.1
  • 4.0.1.0
  • 1.92.3.8643
  • 0.0.0.0
Internal Name
  • DotSetup.dll
  • DotSetupSDK.dll
  • utils_mds.dll
Legal Copyright
  • Copyright
  • Copyright dotSetup.io Open Source Project
  • Copyright Microvirt
  • Copyright Utils MDS.
Original Filename
  • DotSetup.dll
  • DotSetupSDK.dll
  • utils_mds.dll
Product Name
  • DotSetup
  • DotSetupSDK Installer
  • MDUtils
  • Microvirt Installer
Product Version
  • 4.0.1.1
  • 4.0.1.0
  • 1.92.3.8643
  • 0.0.0.0

Digital Signatures

Signer Root Status
Noviadigm Sectigo Public Code Signing Root R46 Root Not Trusted

Block Information

Total Blocks: 78
Potentially Malicious Blocks: 36
Whitelisted Blocks: 38
Unknown Blocks: 4

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x ? x ? ? x x x x x ? x 0 x 0 x x x x x x 0 0 0 0 0 0 x x 0 0 x 0 0 x x x x x x x x x x 0 x 0 0 0 x x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • DotSetupIo.A
  • DotSetupIo.B

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtDuplicateToken
Show More
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • UNKNOWN
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\5c2b9b9124dc4b8c8d561e18f87e3a37d2fbf0a0_0000316408.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\f8e8813fb218ed652f7e554584dadd30ef034ed9_0000300056.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\6f01e7ebacbcf1630dc06523273b3da94dfb2b65_0000316408.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\0246c4234093c5a675a587da1a357de11be25111_0000316408.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\53449fc3b38e1e63b1d1e8e19197b7f8fcec77f5_0000228536.,LiQMAxHB
Show More
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\d62d711f014313b80812a2cb638dd10b469d38c5_0000316408.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\7583baf0d1bdad6f3c8b3d0a0f75a8ecf7a02810_0000300056.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\d8caec4a69839dbd1f35399d2e0e848aa6636aad_0000300056.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\b2876ab53c143494829c744ff4620433834a13e1_0000316408.,LiQMAxHB

Related Posts

Trending

Most Viewed

Loading...