PUP.Fusion
Table of Contents
Analysis Report
General information
| Family Name: | PUP.Fusion |
|---|---|
| Signature status: | No Signature |
Known Samples
Known Samples
This section lists other file samples believed to be associated with this family.|
MD5:
4aedd570c3fbd359c419c386c1ca1d7b
SHA1:
0271faf4b3f832ec0b66509934b7f6f8d4480ff5
File Size:
174.08 KB, 174080 bytes
|
|
MD5:
b99aa2a26f229630ce526cbc9d76a4fd
SHA1:
0083423215b1d8617893cfee5991b96e141d86e2
File Size:
5.95 MB, 5950692 bytes
|
|
MD5:
46cf2353c9f1b052071eefeaaa3fdd15
SHA1:
dedd33aa3acd33e2c7e2d0b2563fcc64aff106e7
SHA256:
E136939365CDBAF0B1E03B0F3B7E23F9B6022F7F1AF70911A179C2D680B41A08
File Size:
5.95 MB, 5950875 bytes
|
|
MD5:
e2611802329da544b63d582e9b9869b3
SHA1:
e89c0e74070873ccb3bd72de98ba0352a25903dc
SHA256:
0BC5D098D4A13EEAAB468B129BDC823FE2BC3AFE1147DA737A580F18CE41ECDE
File Size:
5.94 MB, 5935082 bytes
|
|
MD5:
3eeac235bf63583650d02168c30ac179
SHA1:
1618d4e33e4a1237a2f2776fc138dea595c99c38
SHA256:
BDBC45F1BA4D54063AB051B1898B2A1A0C2BDB6D74894BB739CF6CAC59DCB9A5
File Size:
2.11 MB, 2109440 bytes
|
Show More
|
MD5:
fe407f31c504b36da8456776c6012312
SHA1:
f4e303cdb26e32406d41ff937a41401bae77618f
SHA256:
0BDB8C15CBCFD25D88A62D57F435A757578F91710200837D503EA406FBCDF411
File Size:
1.94 MB, 1935360 bytes
|
|
MD5:
32ca2c40d234c1eaf7cefd769c0dd638
SHA1:
8bbbb9d66ffbc8b7ce46e178be5c92323bc9c1da
SHA256:
30C5D373B179E8CFF35277AC5E6E7F8DDE3606095A2A5474AB70174E4237683D
File Size:
5.94 MB, 5941426 bytes
|
Windows Portable Executable Attributes
- File doesn't have "Rich" header
- File doesn't have debug information
- File doesn't have exports table
- File doesn't have relocations information
- File doesn't have security information
- File is 32-bit executable
- File is either console or GUI application
- File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
- File is Native application (NOT .NET application)
- File is not packed
Show More
- IMAGE_FILE_DLL is not set inside PE header (Executable)
- IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)
File Icons
File Icons
This section displays icon resources found within family samples. Malware often replicates icons commonly associated with legitimate software to mislead users into believing the malware is safe.Windows PE Version Information
Windows PE Version Information
This section displays values and attributes that have been set in the Windows file version information data structure for samples within this family. To mislead users, malware actors often add fake version information mimicking legitimate software.| Name | Value |
|---|---|
| Comments |
|
| Company Name |
|
| File Description |
|
| File Version |
|
| Legal Copyright |
|
| Product Name |
|
| Product Version |
|
Files Modified
Files Modified
This section lists files that were created, modified, moved and/or deleted by samples in this family. File system activity can provide valuable insight into how malware functions on the operating system.| File | Attributes |
|---|---|
| c:\users\user\appdata\local\temp\000069c6.log | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\00007399.log | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\000073a9.log | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\ns20417f1c\57dfba85.tmp | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsd2709332656\bootstrap_4598.html | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsd2709332656\css\ie6_main.css | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsd2709332656\css\ie6_main.css | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\css\ie6_main.css | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\css\main.css | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsd2709332656\css\main.css | Generic Write,Read Attributes |
Show More
| c:\users\user\appdata\local\temp\nsd2709332656\css\main.css | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\css\sdk-ui\browse.css | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsd2709332656\css\sdk-ui\browse.css | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\css\sdk-ui\browse.css | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\css\sdk-ui\button.css | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsd2709332656\css\sdk-ui\button.css | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\css\sdk-ui\button.css | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\css\sdk-ui\checkbox.css | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsd2709332656\css\sdk-ui\checkbox.css | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\css\sdk-ui\checkbox.css | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\css\sdk-ui\images\button-bg.png | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsd2709332656\css\sdk-ui\images\button-bg.png | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\css\sdk-ui\images\button-bg.png | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\css\sdk-ui\images\progress-bg-corner.png | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsd2709332656\css\sdk-ui\images\progress-bg-corner.png | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\css\sdk-ui\images\progress-bg-corner.png | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\css\sdk-ui\images\progress-bg.png | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsd2709332656\css\sdk-ui\images\progress-bg.png | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\css\sdk-ui\images\progress-bg.png | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\css\sdk-ui\images\progress-bg2.png | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsd2709332656\css\sdk-ui\images\progress-bg2.png | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\css\sdk-ui\images\progress-bg2.png | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\css\sdk-ui\progress-bar.css | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsd2709332656\css\sdk-ui\progress-bar.css | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\css\sdk-ui\progress-bar.css | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\csshover3.htc | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsd2709332656\csshover3.htc | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\csshover3.htc | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\images\loader.gif | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsd2709332656\images\loader.gif | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\images\loader.gif | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\af.locale | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\af.locale | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\af.locale | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\az.locale | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\az.locale | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\az.locale | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\be.locale | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\be.locale | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\be.locale | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\bg.locale | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\bg.locale | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\bg.locale | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\bs.locale | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\bs.locale | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\bs.locale | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\ca.locale | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\ca.locale | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\ca.locale | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\cs.locale | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\cs.locale | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\cs.locale | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\da.locale | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\da.locale | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\da.locale | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\de.locale | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\de.locale | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\de.locale | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\el.locale | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\el.locale | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\el.locale | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\en.locale | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\en.locale | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\en.locale | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\es.locale | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\es.locale | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\es.locale | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\et.locale | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\et.locale | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\et.locale | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\eu.locale | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\eu.locale | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\eu.locale | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\fa.locale | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\fa.locale | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\fa.locale | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\fi.locale | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\fi.locale | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\fi.locale | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\fr.locale | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\fr.locale | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\fr.locale | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\gu.locale | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\gu.locale | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\gu.locale | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\he.locale | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\he.locale | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\he.locale | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\hi.locale | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\hi.locale | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\hi.locale | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\hr.locale | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\hr.locale | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\hr.locale | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\ht.locale | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\ht.locale | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\ht.locale | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\hu.locale | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\hu.locale | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\hu.locale | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\hy.locale | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\hy.locale | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\hy.locale | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\id.locale | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\id.locale | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\id.locale | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\is.locale | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\is.locale | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\is.locale | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\it.locale | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\it.locale | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\it.locale | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\ja.locale | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\ja.locale | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\ja.locale | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\ka.locale | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\ka.locale | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\ka.locale | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\kk.locale | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\kk.locale | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\kk.locale | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\ko.locale | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\ko.locale | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\ko.locale | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\ku.locale | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\ku.locale | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\ku.locale | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\lo.locale | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\lo.locale | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\lo.locale | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\lt.locale | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\lt.locale | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\lt.locale | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\lv.locale | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\lv.locale | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\lv.locale | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\mk.locale | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\mk.locale | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\mk.locale | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\ml.locale | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\ml.locale | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\ml.locale | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\mr.locale | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\mr.locale | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\mr.locale | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\ms.locale | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\ms.locale | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\ms.locale | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\ne.locale | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\ne.locale | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\ne.locale | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\nl.locale | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\nl.locale | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\nl.locale | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\no.locale | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\no.locale | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\no.locale | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\pa.locale | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\pa.locale | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\pa.locale | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\pl.locale | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\pl.locale | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\pl.locale | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\ps.locale | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\ps.locale | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\ps.locale | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\pt.locale | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\pt.locale | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\pt.locale | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\ro.locale | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\ro.locale | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\ro.locale | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\ru.locale | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\ru.locale | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\ru.locale | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\sk.locale | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\sk.locale | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\sk.locale | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\sl.locale | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\sl.locale | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\sl.locale | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\sq.locale | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\sq.locale | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\sq.locale | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\sr.locale | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\sr.locale | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\sr.locale | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\sv.locale | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\sv.locale | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsd2709332656\locale\sv.locale | Synchronize,Write Attributes |
51 additional files are not displayed above.
Registry Modifications
Registry Modifications
This section lists registry keys and values that were created, modified and/or deleted by samples in this family. Windows Registry activity can provide valuable insight into malware functionality. Additionally, malware often creates registry values to allow itself to automatically start and indefinitely persist after an initial infection has compromised the system.| Key::Value | Data | API Name |
|---|---|---|
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\5.0\cache\content::cacheprefix | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\5.0\cache\cookies::cacheprefix | Cookie: | RegNtPreCreateKey |
| HKCU\software\microsoft\windows\currentversion\internet settings\5.0\cache\history::cacheprefix | Visited: | RegNtPreCreateKey |
Windows API Usage
Windows API Usage
This section lists Windows API calls that are used by the samples in this family. Windows API usage analysis is a valuable tool that can help identify malicious activity, such as keylogging, security privilege escalation, data encryption, data exfiltration, interference with antivirus software, and network request manipulation.| Category | API |
|---|---|
| Anti Debug |
|
| User Data Access |
|