PUP.Fusion.CA
The detection of PUP.Fusion.CA on your system indicates the presence of a potentially unwanted program (PUP) that may be causing issues with your computer's performance and security. It's essential to understand what this detection means and how to properly remove the threat to prevent further problems.
Table of Contents
What Is PUP.Fusion.CA?
PUP.Fusion.CA is a type of malware that is classified as a potentially unwanted program. This category of threats includes software that may not be malicious in nature but can still cause problems for users, such as displaying unwanted advertisements, collecting user data without consent, or modifying system settings. PUPs can often be installed alongside other software, and users may not even be aware that they are present on their system.
How PUP.Fusion.CA Operates
PUPs like PUP.Fusion.CA typically operate by installing themselves on a system through various means, such as bundled software downloads or exploited vulnerabilities. Once installed, they can begin to collect user data, display unwanted ads, or modify system settings to suit their purpose. In some cases, PUPs can also download and install additional malware or software without the user's knowledge or consent.
It's worth noting that PUPs can be particularly tricky to detect, as they often disguise themselves as legitimate software or system files. This is why it's crucial to have a reputable antivirus program installed on your system, as well as to practice safe browsing habits and be cautious when downloading software from the internet.
Symptoms of Infection
If your system is infected with PUP.Fusion.CA, you may notice a range of symptoms, including slowed system performance, unwanted advertisements or pop-ups, and modified system settings. You may also notice that your browser homepage or search engine has been changed without your consent, or that you are being redirected to unwanted websites. In some cases, PUPs can also cause system crashes or freezes, or lead to the installation of additional malware.
- Unwanted ads or pop-ups
- Modified system settings
- Slow system performance
- Browser redirects or hijacking
- System crashes or freezes
How to Remove PUP.Fusion.CA
- Boot your system into Safe Mode with Networking to prevent the PUP from loading and to allow for a more thorough removal process.
- Download and install a reputable anti-malware tool, such as SpyHunter, and perform a full scan of your system to detect and remove any malware or PUPs.
- Uninstall any suspicious programs or software that may be related to the PUP, taking care to follow the proper uninstallation procedures to avoid causing further system issues.
- Reset your browser settings to their default values, including Chrome, Firefox, and Edge, to remove any modifications made by the PUP.
- Reboot your system and perform a follow-up scan with your anti-malware tool to ensure that all remnants of the PUP have been removed.
Conclusion
The detection of PUP.Fusion.CA on your system is a serious issue that requires prompt attention to prevent further problems. By understanding what this detection means and following the proper removal procedures, you can help to protect your system and your personal data from potential harm. Remember to always practice safe browsing habits, keep your antivirus software up to date, and be cautious when downloading software from the internet to minimize the risk of PUP infections in the future.
Analysis Report
General information
| Family Name: | PUP.Fusion.CA |
|---|---|
| Signature status: | Self Signed |
Known Samples
Known Samples
This section lists other file samples believed to be associated with this family.|
MD5:
21f18d818834328e0ba1ea556385f609
SHA1:
d9f941f4995316c4df1279b1c45294ff89cee393
File Size:
7.82 MB, 7815232 bytes
|
|
MD5:
b7e436d249a9ca53701a7bfe7b0105a7
SHA1:
e2b3da8b2fbc80c8250f367544488af0ee0f9103
SHA256:
C2E3A34CA6451327187332AD50191C90BDC0B9654C9C19A0ACE6FB7E581E372C
File Size:
181.33 KB, 181328 bytes
|
|
MD5:
816e7812c6157896736c3e4724ebc747
SHA1:
0a8a2ef7676ece03eec1d6a64f62ef1a62c87d8c
SHA256:
11136A76F19A3704A791CC0A314DF0A6C2D6718D6DCCB796EA7374C7D4DA3053
File Size:
9.88 MB, 9875152 bytes
|
|
MD5:
4c911f748f3db62b65bfa9184920cc48
SHA1:
97aec668ffe74c0cd3b1f4f814b1b429506c4124
SHA256:
32B4D8573E266992CDFA8BD8750A184011FEECA6BA3B3FE765BE9EE9411767F7
File Size:
1.25 MB, 1247296 bytes
|
|
MD5:
9522f82628f5f111536c7499548812d1
SHA1:
e493e13717df2fc0dba8a1857e88da7e3d7acda0
SHA256:
FA949AA3A4C4AB1A1633AF62B348070E3F1CF8C11C30A23423A004726FFC5080
File Size:
9.35 MB, 9350344 bytes
|
Show More
|
MD5:
649331ca1070065605e2f188f50c4f37
SHA1:
6a4161084765e75508c01edb034c7d3f24c7feb3
SHA256:
6CB6339840F23F5D19D6108D7BA55408884890D6E89822C1B75C20642795BCEE
File Size:
7.45 MB, 7449368 bytes
|
|
MD5:
e34123c4cdbf6aa06216b08a3c1050fc
SHA1:
362a5dc6737d3fdce0ca0c3591e75467e0f823cc
SHA256:
5F71875B2AF2BA41D15FE65C9A5D866FC937DAE358EB273724522A28D55773AD
File Size:
8.87 MB, 8872768 bytes
|
|
MD5:
dfcd71076ed714e27faf0fd18d5bdc39
SHA1:
ec93eb412f442a2ec9dd650f0924a864fe83290d
SHA256:
9D89FD0D4926C359298B518B28D9EDDC4B6193FA930C33A5EEFFF18FDE1C5037
File Size:
8.87 MB, 8872728 bytes
|
|
MD5:
d24053fee9dd954ff0dbb00482f3a7a2
SHA1:
01fd442a6a4dc5a2be1611f6448ae15dd547f4fb
SHA256:
C2A49D2BAE58E0054CD4B72067B0FB6C1878573D6AD585411134AC919EB05E9E
File Size:
9.50 MB, 9502584 bytes
|
|
MD5:
94f3a24921e9d6ed32f0f9750b18f862
SHA1:
57e3ed19a640b9b3f76d8e293b602b729ad33027
SHA256:
BADA0EE243477753D74184ADF881DB3F942AE6CF744ACDB802CE35FD7BF19A1E
File Size:
3.09 MB, 3088702 bytes
|
|
MD5:
acd9e2757f243f4f8c6eaa71788de635
SHA1:
950275323caa631062580ef48164b70f2d67ca51
SHA256:
4D2DBE0428B62934F42180CAFE575AA8DB1F164FC73C3B085EDF9F36A9000E2E
File Size:
5.16 MB, 5157682 bytes
|
|
MD5:
15cdb832e51f3d3fd6ad6ed557741e47
SHA1:
b680144b2e68d4846d4ba991e18fa2a1b9a19f56
SHA256:
C007F89EEC6F226F32D27246C5189DE465985B6E60899A3B07D78D667387B1AF
File Size:
1.74 MB, 1743120 bytes
|
|
MD5:
d825e217316bfef3a62ddfd34198af96
SHA1:
9a5e8be00319f4d7e4276a171d56ffa895a26fb3
SHA256:
6904401EA854D0767BDDA8895000E1BA1CD6A461201ABFC2129920D4CF527F4C
File Size:
809.62 KB, 809624 bytes
|
|
MD5:
9f79ba3d79e64ebc44bf6a08f6d335db
SHA1:
da1f8f1ad487841c4cee5b8a38528dfc25b7fcf8
SHA256:
BB358EF3FB38E5A29F30B82B6307AC2D61CD6C9C15BCDB0FAD54CDEC3CD1380A
File Size:
9.44 MB, 9439768 bytes
|
|
MD5:
bae713703774d63cba44d3b7b2e5c559
SHA1:
f0a73fc1080f88b62181cbcda5db07e918789a76
SHA256:
3E1CA6C8B081BF990FD88D5E0E41E01A8F20DC185418E0FD2FFA9BF173D51829
File Size:
5.96 MB, 5960240 bytes
|
|
MD5:
045ca3e4d3651490281d3d6b8ad93afa
SHA1:
3d443367e65da504cf848a3e4bc53ada7f63f9ef
SHA256:
6F151E5E1DB98B7254D2FFAEDFE85622562D323640E78E24EECAA69818D40216
File Size:
7.94 MB, 7943536 bytes
|
|
MD5:
b24aa2ffd0ab58354f136868f23f8fa0
SHA1:
a6f2e698f879dc5a2ac2c92914965bd915ed5411
SHA256:
AB4614068301C290E434EA83C5896A0956023C2A802099E7361E6678F3D7D500
File Size:
1.74 MB, 1742744 bytes
|
|
MD5:
b1165aee310913c7afaffa2e210b4da0
SHA1:
8f3ff08298ed5b9c8062de47e6498dbc60ad06df
SHA256:
963CB6CBE0D9CB4E9F4CEFB906F8D68C206E57EE6C8FB33AE1D4AE117C81245C
File Size:
3.91 MB, 3908468 bytes
|
|
MD5:
87c0d8851613624861423bf317936048
SHA1:
3c165de270a4fed8d8dbdcf1a98ccdfa20d8fb51
SHA256:
2C14AD2C59B7F76AA578FF04E22CEA7A1B70A15D880ABF26344F96CB29FA809B
File Size:
1.74 MB, 1743104 bytes
|
|
MD5:
9485db7a0ccf5c3a9e256085cdf4947c
SHA1:
19d5fe10cc7c92c8da9eed4c72f4c953599baa59
SHA256:
CC516ED7764864DDACC212338583652039940CE771DBC9DD76CE86CA59711D15
File Size:
9.47 MB, 9465816 bytes
|
Windows Portable Executable Attributes
- File doesn't have "Rich" header
- File doesn't have debug information
- File doesn't have exports table
- File doesn't have relocations information
- File doesn't have security information
- File is 32-bit executable
- File is either console or GUI application
- File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
- File is Native application (NOT .NET application)
- File is not packed
Show More
- IMAGE_FILE_DLL is not set inside PE header (Executable)
- IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)
File Icons
File Icons
This section displays icon resources found within family samples. Malware often replicates icons commonly associated with legitimate software to mislead users into believing the malware is safe.Show More
Windows PE Version Information
Windows PE Version Information
This section displays values and attributes that have been set in the Windows file version information data structure for samples within this family. To mislead users, malware actors often add fake version information mimicking legitimate software.| Name | Value |
|---|---|
| Comments |
|
| Company Name |
|
| File Description |
|
| File Version |
|
| Legal Copyright |
|
| Legal Trademarks | IM-Magic |
| Original Filename | StrimSetup.exe |
| Product Name |
|
| Product Version |
|
Digital Signatures
Digital Signatures
This section lists digital signatures that are attached to samples within this family. When analyzing and verifying digital signatures, it is important to confirm that the signature’s root authority is a well-known and trustworthy entity and that the status of the signature is good. Malware is often signed with non-trustworthy “Self Signed” digital signatures (which can be easily created by a malware author with no verification). Malware may also be signed by legitimate signatures that have an invalid status, and by signatures from questionable root authorities with fake or misleading “Signer” names.| Signer | Root | Status |
|---|---|---|
| Comodo Security Solutions | COMODO RSA Certification Authority | Root Not Trusted |
| Comodo Security Solutions, Inc | COMODO RSA Extended Validation Code Signing CA | Self Signed |
| Glarysoft LTD | DigiCert Assured ID Code Signing CA-1 | Self Signed |
| Logitech Inc | DigiCert EV Code Signing CA (SHA2) | Self Signed |
| Glarysoft LTD | DigiCert SHA2 Assured ID Code Signing CA | Self Signed |
Show More
| Sigma Resources & Technologies, Inc. | DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 | Self Signed |
| POLL EVERYWHERE, INC. | Go Daddy Root Certificate Authority - G2 | Root Not Trusted |
| Comodo Security Solutions Inc | Sectigo Public Code Signing Root R46 | Root Not Trusted |
| Comodo Security Solutions, Inc. | UTN-USERFirst-Object | Root Not Trusted |
| Nicetex Limited | VeriSign Class 3 Code Signing 2010 CA | Self Signed |
| Dreamsecurity Co., Ltd. | thawte SHA256 Code Signing CA | Self Signed |
File Traits
- 7-zip (In Overlay)
- 7-zip SFX
- dll
- Installer Manifest
- nosig nsis
- Nullsoft Installer
- packed
- x86
Files Modified
Files Modified
This section lists files that were created, modified, moved and/or deleted by samples in this family. File system activity can provide valuable insight into how malware functions on the operating system.| File | Attributes |
|---|---|
| \device\namedpipe | Generic Read,Write Attributes |
| \device\namedpipe | Generic Write,Read Attributes |
| \device\namedpipe\gmdasllogger | Generic Write,Read Attributes |
| c:\programdata\pollev_xp_util.exe | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\logifeinstallerforlync2013v1.2.289\logifeplugininstaller.exe | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\logifeinstallerforlync2013v1.2.289\setup.exe | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\logifeinstallerforlync2013v1.2.289\setup.ini | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsba4d7.tmp\advsplash.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsba4d7.tmp\iospecial.ini | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsba4d7.tmp\iospecial.ini | Generic Write,Read Attributes |
Show More
| c:\users\user\appdata\local\temp\nsba4d7.tmp\langdll.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsba4d7.tmp\logo.bmp | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsba4d7.tmp\logo.bmp | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\nsba4d7.tmp\modern-header.bmp | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsba4d7.tmp\modern-wizard.bmp | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsba4d7.tmp\nsprocess.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsba4d7.tmp\setup.ini | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsba4d7.tmp\setup.ini | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsba4d7.tmp\system.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsba4d7.tmp\warning.ini | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsba4d7.tmp\warning.ini | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsbbd5b.tmp\modern-header.bmp | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsbbd5b.tmp\modern-wizard.bmp | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsbbd5b.tmp\modern-wizard.bmp | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\nsbbd5b.tmp\nsdialogs.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsbbd5b.tmp\quickstartup.ini | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsc63ec.tmp\langdll.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsdaa07.tmp\killprocdll.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsdaa07.tmp\nsexec.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsdaa07.tmp\system.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsdaa07.tmp\version.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nse6624.tmp\langdll.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nse6ff2.tmp\bottom.bmp | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nse6ff2.tmp\content.bmp | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nse6ff2.tmp\installhelperplugin.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nse6ff2.tmp\installoptions.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nse6ff2.tmp\modern-header.bmp | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nse6ff2.tmp\nsis_skincrafter_plugin.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nse6ff2.tmp\rbskin.skf | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nse6ff2.tmp\skincrafter.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nse6ff2.tmp\skinnsis.skf | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nse6ff2.tmp\system.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nse6ff2.tmp\uninstall.bmp | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nse6ff2.tmp\uninstallfeedbackpage.ini | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nse6ff2.tmp\uninstallfeedbackpage.ini | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsf4bbb.tmp\bottom.bmp | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsf4bbb.tmp\content.bmp | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsf4bbb.tmp\installhelperplugin.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsf4bbb.tmp\installoptions.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsf4bbb.tmp\modern-header.bmp | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsf4bbb.tmp\nsis_skincrafter_plugin.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsf4bbb.tmp\rbskin.skf | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsf4bbb.tmp\skincrafter.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsf4bbb.tmp\skinnsis.skf | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsf4bbb.tmp\system.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsf4bbb.tmp\uninstall.bmp | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsf4bbb.tmp\uninstallfeedbackpage.ini | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsf4bbb.tmp\uninstallfeedbackpage.ini | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsf7969.tmp\modern-header.bmp | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsf7969.tmp\modern-wizard.bmp | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsf7969.tmp\modern-wizard.bmp | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\nsf7969.tmp\nsdialogs.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsf7969.tmp\system.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsf7969.tmp\trackseraser.ini | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsgbd7a.tmp\modern-wizard.bmp | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsgbd7a.tmp\nsdialogs.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsgbd7a.tmp\system.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsgbd7a.tmp\version.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsh3c21.tmp | Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete |
| c:\users\user\appdata\local\temp\nsha852.tmp\langdll.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsifab8.tmp\system.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsifab8.tmp\version.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsl6757.tmp\bottom.bmp | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsl6757.tmp\content.bmp | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsl6757.tmp\installhelperplugin.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsl6757.tmp\installoptions.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsl6757.tmp\modern-header.bmp | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsl6757.tmp\nsis_skincrafter_plugin.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsl6757.tmp\rbskin.skf | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsl6757.tmp\skincrafter.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsl6757.tmp\skinnsis.skf | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsl6757.tmp\system.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsl6757.tmp\uninstall.bmp | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsl6757.tmp\uninstallfeedbackpage.ini | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsl6757.tmp\uninstallfeedbackpage.ini | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nslbcfd.tmp\langdll.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsm4320.tmp | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\nsm4320.tmp\version.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsm4320.tmp\version.dll | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\nsna824.tmp\langdll.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsna824.tmp\nsprocess.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsnbc9d.tmp\modern-header.bmp | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsnbc9d.tmp\modern-wizard.bmp | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsnbc9d.tmp\modern-wizard.bmp | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\nsnbc9d.tmp\nsdialogs.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsnbc9d.tmp\system.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsnbc9d.tmp\trackseraser.ini | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nso5546.tmp\diskcleaner.ini | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nso5546.tmp\modern-header.bmp | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nso5546.tmp\modern-wizard.bmp | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nso5546.tmp\modern-wizard.bmp | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\nso5546.tmp\nsdialogs.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nso5546.tmp\system.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nssa842.tmp | Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete |
| c:\users\user\appdata\local\temp\nsx3c32.tmp\installoptions.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsx3c32.tmp\iospecial.ini | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsx3c32.tmp\iospecial.ini | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsx3c32.tmp\modern-wizard.bmp | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsx3c32.tmp\system.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsx51e9.tmp\diskcleaner.ini | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsx51e9.tmp\modern-header.bmp | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsx51e9.tmp\modern-wizard.bmp | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsx51e9.tmp\modern-wizard.bmp | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\nsx51e9.tmp\nsdialogs.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsx51e9.tmp\system.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsxa813.tmp | Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete |
| c:\users\user\appdata\local\temp\nsy6982.tmp\killprocdll.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsy6982.tmp\nsexec.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsy6982.tmp\system.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsy6982.tmp\version.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsz4841.tmp\modern-wizard.bmp | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsz4841.tmp\system.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsz4841.tmp\version.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\uninstallfeedbackpagelayout.ini | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\~nsu.tmp\au_.exe | Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144 |
| c:\users\user\appdata\local\temp\~nsua.tmp\un_a.exe | Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144 |
| c:\windows\syswow64\mfc71.dll | Generic Write,Read Attributes |
| c:\windows\syswow64\msvcr71.dll | Generic Write,Read Attributes |
| c:\windows\temp\comodo logsfolder\generate_dragon_uninstaller.log | Generic Write,Read Attributes |
Registry Modifications
Registry Modifications
This section lists registry keys and values that were created, modified and/or deleted by samples in this family. Windows Registry activity can provide valuable insight into malware functionality. Additionally, malware often creates registry values to allow itself to automatically start and indefinitely persist after an initial infection has compromised the system.| Key::Value | Data | API Name |
|---|---|---|
| HKLM\system\controlset001\control\session manager::pendingfilerenameoperations | \??\C:\Users\Uwrkzkql\AppData\Local\Temp\~nsuA.tmp\Un_A.exe | RegNtPreCreateKey |
| HKLM\system\controlset001\control\session manager::pendingfilerenameoperations | \??\C:\Users\Uwrkzkql\AppData\Local\Temp\~nsuA.tmp\Un_A.exe \??\C:\Users\Uwrkzkql\AppData\Local\Temp\~nsuA.tmp | RegNtPreCreateKey |
| HKLM\software\wow6432node\microsoft\jet\4.0\engines\jet 4.0::maxbuffersize | 썐 | RegNtPreCreateKey |
| HKLM\system\controlset001\control\session manager::pendingfilerenameoperations | \??\C:\Users\Rcoqvqgn\AppData\Local\Temp\~nsuA.tmp\Un_A.exe | RegNtPreCreateKey |
| HKLM\system\controlset001\control\session manager::pendingfilerenameoperations | \??\C:\Users\Rcoqvqgn\AppData\Local\Temp\~nsuA.tmp\Un_A.exe \??\C:\Users\Rcoqvqgn\AppData\Local\Temp\~nsuA.tmp | RegNtPreCreateKey |
| HKLM\system\controlset001\control\session manager::pendingfilerenameoperations | \??\C:\Users\Xlfdqrpg\AppData\Local\Temp\nsm4320.tmp\ | RegNtPreCreateKey |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect | RegNtPreCreateKey |
Show More
| HKLM\system\controlset001\control\session manager::pendingfilerenameoperations | \??\C:\Users\Xvvnrbbd\AppData\Local\Temp\~nsu.tmp\Au_.exe | RegNtPreCreateKey |
| HKLM\system\controlset001\control\session manager::pendingfilerenameoperations | \??\C:\Users\Xvvnrbbd\AppData\Local\Temp\~nsu.tmp\Au_.exe \??\C:\Users\Xvvnrbbd\AppData\Local\Temp\~nsu.tmp | RegNtPreCreateKey |
| HKCU\software\microsoft\windows\currentversion\internet settings\zones\2::1406 | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zones\2::1607 | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zones\2::currentlevel | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zones\3::1406 | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zones\3::1607 | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zones\3::currentlevel | RegNtPreCreateKey | |
| HKLM\software\wow6432node\microsoft\windows\currentversion\internet settings\zones\2::1406 | RegNtPreCreateKey | |
| HKLM\software\wow6432node\microsoft\windows\currentversion\internet settings\zones\2::1607 | RegNtPreCreateKey | |
| HKLM\software\wow6432node\microsoft\windows\currentversion\internet settings\zones\2::currentlevel | RegNtPreCreateKey | |
| HKLM\software\wow6432node\microsoft\windows\currentversion\internet settings\zones\3::1406 | RegNtPreCreateKey | |
| HKLM\software\wow6432node\microsoft\windows\currentversion\internet settings\zones\3::1607 | RegNtPreCreateKey | |
| HKLM\software\wow6432node\microsoft\windows\currentversion\internet settings\zones\3::currentlevel | RegNtPreCreateKey | |
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe | 苑ꬅ憔ǜ | RegNtPreCreateKey |
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe | ㉔곛憔ǜ | RegNtPreCreateKey |
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe | 㒹䑔鰇ǜ | RegNtPreCreateKey |
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe | ⾟䙶鰇ǜ | RegNtPreCreateKey |
Windows API Usage
Windows API Usage
This section lists Windows API calls that are used by the samples in this family. Windows API usage analysis is a valuable tool that can help identify malicious activity, such as keylogging, security privilege escalation, data encryption, data exfiltration, interference with antivirus software, and network request manipulation.| Category | API |
|---|---|
| Anti Debug |
|
| User Data Access |
|
| Process Shell Execute |
|
| Other Suspicious |
|
| Process Manipulation Evasion |
|
| Keyboard Access |
|
| Syscall Use |
Show More
|
| Network Winsock2 |
|
| Service Control |
|
| Encryption Used |
|
| Process Terminate |
|
Shell Command Execution
Shell Command Execution
This section lists Windows shell commands that are run by the samples in this family. Windows Shell commands are often leveraged by malware for nefarious purposes and can be used to elevate security privileges, download and launch other malware, exploit vulnerabilities, collect and exfiltrate data, and hide malicious activity.
"C:\Users\Uwrkzkql\AppData\Local\Temp\~nsuA.tmp\Un_A.exe" _?=c:\users\user\downloads\
|
"C:\Users\Rcoqvqgn\AppData\Local\Temp\~nsuA.tmp\Un_A.exe" _?=c:\users\user\downloads\
|
"C:\Users\Xlfdqrpg\AppData\Local\Temp\LogiFEInstallerforLync2013v1.2.289\setup.exe"
|
open LogiFEpluginInstaller.exe
|
"C:\Users\Xvvnrbbd\AppData\Local\Temp\~nsu.tmp\Au_.exe" _?=c:\users\user\downloads\
|
Show More
netsh advfirewall firewall delete rule name="GPKISecureWebNP" program="C:\Program Files (x86)\GPKISecureWebNP\GPKISecureWebNP.exe"
|
netsh advfirewall firewall add rule name="GPKISecureWebNP" dir=in action=allow program="C:\Program Files (x86)\GPKISecureWebNP\GPKISecureWebNP.exe" enable=yes
|