Threat Database Hacktool PUP.HackKMS.O

PUP.HackKMS.O

Analysis Report

General information

Family Name: PUP.HackKMS.O
Signature status: No Signature

Known Samples

MD5: 7ef0b827bf036785a9c9a71d10bb9e43
SHA1: e0e7cc9fd7e3cf8f1c00d2cd24563d09382bb3c1
SHA256: 66458F97631BC5AA45B27D4851E2DC43ED720584A36F46CA3359A08E3E93E7C3
File Size: 39.96 KB, 39956 bytes
MD5: 2cc4b841d8a7c3dd82b3a47349366163
SHA1: eb3717603c7d9405c38691b5dcd1280d19f49583
SHA256: 4216D1C42D95CDC4EC442C889B2B73815D2E390D9D02DEED446D0DAEFB49666E
File Size: 39.96 KB, 39956 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have resources
  • File doesn't have security information
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • HighEntropy
  • No Version Info
  • x86

Block Information

Total Blocks: 90
Potentially Malicious Blocks: 54
Whitelisted Blocks: 13
Unknown Blocks: 23

Visual Map

1 2 1 0 1 x x x ? x x x x x x x x 0 x x 0 ? ? x ? ? x x ? ? x x ? ? x x 0 x x x x x x x x x 0 x x x x x x x 0 x x x x x x x x 0 ? ? ? x ? ? x ? 0 0 ? ? x x x x ? ? x ? ? x ? x x ?
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • HackKMS.O

Windows API Usage

Category API
Service Control
  • StartServiceCtrlDispatcher

Trending

Most Viewed

Loading...