Threat Database Hacktool PUP.Hacktool.B

PUP.Hacktool.B

The detection of PUP.Hacktool.B on your system indicates the presence of a potentially unwanted program (PUP) that may pose a risk to your computer's security and performance. It is essential to understand the nature of this threat and take prompt action to remove it. In this report, we will provide an overview of PUP.Hacktool.B, its operating methods, symptoms of infection, and a step-by-step guide on how to remove it from your system.

What Is PUP.Hacktool.B?

PUP.Hacktool.B is a type of potentially unwanted program that is categorized as a hack tool. This means it may contain features or functionalities that can be used to compromise the security of a computer system or exploit its vulnerabilities. PUPs like PUP.Hacktool.B are often installed without the user's knowledge or consent, frequently bundled with other software or downloaded from untrusted sources.

How PUP.Hacktool.B Operates

PUP.Hacktool.B operates by exploiting system vulnerabilities or using social engineering tactics to gain unauthorized access to computer systems. Once installed, it may perform a variety of malicious activities, such as data theft, keystroke logging, or the installation of additional malware. The specific actions of PUP.Hacktool.B can vary, but its primary goal is to compromise the security and integrity of the infected system.

Symptoms of Infection

Symptoms of a PUP.Hacktool.B infection can be subtle and may not always be immediately apparent. However, common indicators include unexpected system crashes, slow performance, unfamiliar programs or toolbars, and suspicious network activity. Users may also notice pop-ups, ads, or other unwanted content displayed on their browsers. If you have noticed any of these symptoms, it is crucial to take action to remove the malware and protect your system.

  • Unexplained changes in system settings or browser configurations
  • Appearance of unfamiliar icons, shortcuts, or programs
  • Increased frequency of system errors or crashes
  • Slow system performance or responsiveness

How to Remove PUP.Hacktool.B

  1. Boot your computer in Safe Mode with Networking to prevent the malware from loading and to allow for a more effective removal process.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove all components of PUP.Hacktool.B.
  3. Uninstall any suspicious programs or applications that were installed around the time the malware was detected.
  4. Reset your web browsers (Chrome, Firefox, Edge) to their default settings to remove any malicious extensions or add-ons that may have been installed by the malware.
  5. Reboot your computer and perform another full scan with your anti-malware tool to ensure that all remnants of PUP.Hacktool.B have been removed.

Conclusion

Removing PUP.Hacktool.B from your system requires careful attention to detail and a thorough understanding of the malware's operating methods. By following the steps outlined in this report, you can effectively remove the malware and protect your system from future infections. It is also essential to maintain good security practices, such as regularly updating your operating system and software, using strong antivirus programs, and being cautious when downloading or installing new applications. Remember, prevention and vigilance are key to maintaining a secure and healthy computer system.

Analysis Report

General information

Family Name: PUP.Hacktool.B
Signature status: No Signature

Known Samples

MD5: 7403bf81b2ec2242fa02a19e9d5f5948
SHA1: 2e5d3f29fc5285397a6fce59818284dd6509fd9a
SHA256: 6601B662F321391BC7D3153AC065FE17DB04849BF330F1397DCE4EAD57A18052
File Size: 806.91 KB, 806912 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have security information
  • File has exports table
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
File Description PDFCreator Toolbar
File Version 3,3,0,1
Internal Name PDFCreator Toolbar
Legal Copyright Copyright 2006
Original Filename Toolbar.dll
Product Name PDFCreator Toolbar
Product Version 3,3,0,1

File Traits

  • dll
  • HighEntropy
  • x86

Block Information

Total Blocks: 2,738
Potentially Malicious Blocks: 843
Whitelisted Blocks: 1,879
Unknown Blocks: 16

Visual Map

0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x x x 0 0 0 x 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 0 0 0 0 0 x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 x 0 0 0 0 0 0 0 x x x 0 0 0 0 0 0 x x 0 0 x x 0 0 x x 0 x x x 0 0 x x 0 0 x x x x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x x 0 x 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 x x x 0 x x x x x x 0 0 0 x 0 0 x x 0 x x x x x 0 x 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 x x 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x 0 0 0 0 0 0 0 0 0 x 0 x 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x x x x 0 0 0 0 0 x x x x x 0 x x x x x x x x x 0 0 x 0 0 x 0 0 x 0 x x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x x x x 0 x 0 0 0 0 0 x x 0 0 0 x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x 0 0 x x x x x x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 x x x x x 0 x 0 0 0 0 0 0 0 0 0 0 0 x x x x x 0 0 0 0 0 0 0 x x 0 0 x x 0 0 0 0 0 x 0 x 0 x x x x 0 0 x 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 x x 0 x x 0 0 0 0 x x 0 x 0 x x x x 0 0 0 0 x 0 x x x x x x x x x x x 0 0 x 0 0 x x 0 0 0 0 x 0 0 0 0 0 x 0 x 0 x x 0 x x x x x x 0 0 x x x 0 x 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 x x x x 0 x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 x x x x 0 0 x x x x x x x x x x x x x x x x x x x x x x x x 0 x x x x x x 0 0 x x x x x 0 0 x x x 0 0 0 x x x x x x 0 0 0 0 0 x x x x x x 0 x x x x x x x x x x x x x x x x x x x 0 0 x 0 x x x 0 0 0 0 0 0 0 x 0 0 0 x x x 0 0 x x x x x x x x x 0 x x x 0 x x 0 0 0 0 0 0 x 0 x x 0 0 0 0 0 0 0 x 0 x 0 x x x x x x x x x x x x x x x 0 0 x x x x 0 0 x 0 x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x 0 x 0 x x x x x x x 0 x x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x x x x x x 0 0 0 x x x 0 0 0 0 0 0 0 0 0 x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x x x x x x x x x x x x x x x x x x x x 0 0 x x x x x x x x x x x x x 0 0 x 0 x x x ? x 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x x x x x x x 0 0 x x 0 0 x 0 0 x 0 0 x x x x 0 0 0 0 0 x x 0 0 0 0 0 0 x x x 0 0 x x x x x x x x x 0 0 0 0 0 0 0 0 x x x x x x x 0 0 0 0 x x x x 0 0 x x x x x x x 1 x x 0 0 x x x x x x x x 0 x x x 0 x x 0 x x x x x x x x x x x x x 0 0 0 x x 0 0 0 x x x x x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 ? 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 x 0 x x x x x x x 0 0 0 0 x 0 x x 0 x x x x x x 0 0 x x x 0 0 x x x x x x x x x x x x x x x x x x ? ? 0 ? x 0 x 0 ? ? 0 ? ? ? ? ? x ? x ? x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x 0 0 x 0 0 0 0 0 x x x x 0 0 x x x x 0 0 0 x x x x 0 x x x x x x x x x x x 0 x x 0 0 x x 0 0 0 x x 0 0 0 x x x x x x x x x x x x x x x 0 x 0 x x x x 0 0 x x 0 0 x x 0 0 0 0 x x 0 x x x x x 0 0 x x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x x x x x x 0 0 0 0 0 x x x x x 0 0 0 0 0 x 0 0 0 x 0 0 0 0 0 x 0 0 x x 0 0 x 0 x x 0 0 x 0 0 0 0 0 0 x x 0 x 0 0 0 0 0 x x 0 x x x x 0 0 0 0 0 x 0 x 0 0 0 x 0 0 x x x x x x 0 x 0 x x x 1 x 0 x x 0 x x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x 0 x x x x x x 0 x x 0 0 0 x x x 0 0 0 0 x x 0 x x x 0 x 0 x x 0 x x x x x 0 0 0 0 x 0 0 x x x x x x x x x x x 0 x x x x 0 x x 0 x x x x 0 x x 0 0 x x x x x x 0 0 0 x x x x 0 x 0 x x x 0 x x x x x x x x x 0 x x 0 0 x x x x x x x x x x x x x 0 0 x x 0 x 0 x x
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Hacktool.B

Registry Modifications

Key::Value Data API Name
HKLM\software\wow6432node\microsoft\rfc1156agent\currentversion\parameters::trappolltimemillisecs RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtQueryAttributesFile
Show More
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWriteFile
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\2e5d3f29fc5285397a6fce59818284dd6509fd9a_0000806912.,LiQMAxHB

Related Posts

Trending

Most Viewed

Loading...