PUP.HackKMS.LL

Analysis Report

General information

Family Name: PUP.HackKMS.LL
Signature status: No Signature

Known Samples

MD5: 0ccdcee79a9a40b7b09faa1fc03a4b26
SHA1: 8f633f46a76b608ed15778725b0a04a2bceafb1f
SHA256: 76BDE3A873B4858562A8D29CD19AB3E1FF864BCF7BADD72CD0F61A9B775B69A0
File Size: 38.45 KB, 38454 bytes
MD5: 5043e0ff9ae9082f1e31d5c13405a9ed
SHA1: 5d23b47e652ae21ee543175703cc166509288f5e
SHA256: 92DAB3EA40FA6AC0D77C0C08DE015744E5A320FF45B22F6F02F5F2BBBEF3481A
File Size: 38.45 KB, 38454 bytes
MD5: c8d9708f0bc8c67788dead70102a5692
SHA1: f8502330ee11670452bd7db9db12b5e4e06e5a25
SHA256: FEE5EB4012FF8D0B623F7A7AFD905A82E4AF099DDBAE9380A8903FDA153FEF37
File Size: 38.45 KB, 38454 bytes
MD5: 3fc6f3b06e69d5fd9e26d2608650e06b
SHA1: 00a472a900d39250dea99fb89869a8a4bec0758b
SHA256: 4EB2A75BBCBD72A654086390E8CF2B3322C1DECB4B149584CA7BC8C8E6635BE9
File Size: 38.45 KB, 38454 bytes
MD5: 9332374b02027f1314b2fbadbb31794a
SHA1: 97311bf34ba56eaf74f934d6f46b041962a9aacc
SHA256: 775C268F156AACB67C1F8BA2370E12DC088D9F965F1A462FF9E5B1DFD941CBE6
File Size: 38.45 KB, 38454 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have resources
  • File doesn't have security information
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • HighEntropy
  • MZ (In Overlay)
  • No Version Info
  • x86

Block Information

Total Blocks: 49
Potentially Malicious Blocks: 42
Whitelisted Blocks: 7
Unknown Blocks: 0

Visual Map

x x x x x x x x 0 x x x x x x 0 x x x 0 x x x x x x x x x x x x x 0 x x x x x x x x x x x x 1 1 1
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • HackKMS.A
  • HackKMS.AB
  • HackKMS.LL

Windows API Usage

Category API
Service Control
  • StartServiceCtrlDispatcher

Trending

Most Viewed

Loading...