PUP.Keygen.HF

Analysis Report

General information

Family Name: PUP.Keygen.HF
Packers: $Id: UPX
Signature status: No Signature

Known Samples

MD5: 7ca52c1ccc334fca314eceda6d803eec
SHA1: 3755cbad3d0cd53c8c65a1e3aa15e9764d61d56c
File Size: 25.09 KB, 25088 bytes
MD5: 1c2b44d1a61b16057f7a871dc3723be9
SHA1: 9791a5e97646923d4b3bb658987da0aee3bfd8b9
File Size: 12.89 KB, 12895 bytes
MD5: b401efbdaa72049c2be7af1c4e257c84
SHA1: b269a965e5da5f1ba78de92c7737f6aabc2cc36a
File Size: 3.07 KB, 3067 bytes
MD5: 879db177e687b6da99b393c0da590060
SHA1: d0ea0ec2da820ff57654b8fb34b1b683f7077a38
SHA256: 1CD68F1F9AD1F5FD99E82462BC183A7C93C94BDCABD395C3AC1E5E3777F36730
File Size: 3.85 KB, 3853 bytes
MD5: 50c96a7c30f9caf9b1745fc4efa1ca1e
SHA1: 20c54bba7e0603cbd08c799aeb001b44db8781ba
SHA256: 045BC4DD07556B8CEB9F7B2CE1FAF132E3DFE8F169B3C9F3CAF8031E04726825
File Size: 3.28 KB, 3282 bytes
Show More
MD5: 9e1872e0cedd4136bffc4ddf3c181664
SHA1: 2b42a5e5b58ce8519ff640588560f3f783e5f500
SHA256: 7602E63C3BDE768999AC4838ABAACDC6EB73F81A612BF6EB6963BE191151ED12
File Size: 3.82 KB, 3819 bytes
MD5: 350d4a43cdaebd45f2a383fe77081fbe
SHA1: 3e791e095c1cb4ea0a502ef88b0e1939f4feab8e
SHA256: 140F95716C92BBC5D8090997CBAB01D1410442535A61BF8FB2C4CAB4CD7CC8C5
File Size: 15.78 KB, 15780 bytes
MD5: 9d40091c05be4991b8914f6bc817e11f
SHA1: a15fede38bb60402922e0726db152df95e110bae
SHA256: 60A623CD79E2E38E22B9317D5A2FD359D8FDCD68A7537499B9F3A42CF998D834
File Size: 12.96 KB, 12960 bytes
MD5: 5f8e32ca5a738c3f81833535665e4791
SHA1: 0d643389f99e6433976883a0053a11d94f4870b6
SHA256: 95F70189E37BD176AA908B4604B8647E79EC51B4B06C564FE6C0054D7ACCD564
File Size: 18.94 KB, 18944 bytes
MD5: fb68daf0373db0d99a23d0d26643a555
SHA1: 2ff2efa2492b209217eaee7e796558d33f1639b6
SHA256: 75FBB0473B0CE5A44BEADAB15CFB5FDFDEEF775559EF589791F86AC252879011
File Size: 650.94 KB, 650939 bytes
MD5: 51e69dfd6f78de068bfb20f05d5911cf
SHA1: 889fef6fc8dbb218fc2c3e57ca8c310d7e1d4698
SHA256: 89F37F64602221B00CB2A7EC093493E4EF74E41B4C9968D05B79592521B04711
File Size: 4.60 KB, 4604 bytes
MD5: 6e27ee8c71ed2f1285fc2cb4e11d6a35
SHA1: fa4ef240d9a94e6f2082ce17f90cda87b45c4df9
SHA256: 31B5FDA9B9EB3D342457A6BC384B75042F9AA57FBE92A69A9B9AA33536B380B6
File Size: 13.69 KB, 13688 bytes
MD5: efc994441f20123577c79f78b3891cdb
SHA1: 7052144201e05ecc96a25905d3ef0a4dd82482a3
SHA256: 428C540DB61D969940C358E23E9274FE5CA79628836B4B916D348E2A35961CBC
File Size: 2.87 KB, 2872 bytes
MD5: be24548f6924c01cb5c5c85857168346
SHA1: b39eac725b188831cfbafa7a56278f9c616aef10
SHA256: A72A359155AE6FF90A67DA13FA445F82EB1A508CD90A4C5A6C18682A379F2BAD
File Size: 20.48 KB, 20480 bytes
MD5: e89b9058b31abbb8673a60f6ff2fdb80
SHA1: 9c7111ddc5b518ba83be7b3a378445fb666c1b08
SHA256: B3E8E7EDDC7AFFFB1022C6313BC201CF04160B4F1F5F4A5652A801A8808B3E33
File Size: 17.81 KB, 17806 bytes
MD5: 9ba2fb988281bd91467efa26059388a3
SHA1: 8b3447cec076afc5c082170e935963cbe761cd64
SHA256: ACED56EF76D866A532A9A35E67266A651C6A5E6E6657781362FD11A84B8CDBCB
File Size: 12.50 KB, 12496 bytes
MD5: e3d28b5334bf0015fc544c6e67802adb
SHA1: a57f5835f535f986072550facaa7d73096b36886
SHA256: 9CB35C4F7351D517285C9C781419DDBCBB90DFE730E241B52B2FD6B1BF54075F
File Size: 17.72 KB, 17723 bytes
MD5: da3c0a869722833051436b5e4b739a2f
SHA1: adef5b7c92274bf250a11dd25048c06afa2170d3
SHA256: 62E6BC05E5DF2C0D28875473B06921B2E84F4AD67C8AE44C9C7B17C3C494022F
File Size: 3.98 KB, 3983 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have resources
  • File doesn't have security information
  • File has been packed
  • File has TLS information
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
Show More
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

File Traits

  • $Id: UPX
  • 2+ executable sections
  • HighEntropy
  • No Version Info
  • packed
  • upx
  • x86

Block Information

Total Blocks: 10
Potentially Malicious Blocks: 0
Whitelisted Blocks: 3
Unknown Blocks: 7

Visual Map

? ? ? ? ? ? ? 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Dialer.GB
  • GameHack.K
  • Keygen.HF
  • MSIL.Agent.NJA

Files Modified

File Attributes
c:\users\user\appdata\local\temp\nslb37b.tmp\installoptions.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nslb37b.tmp\iospecial.ini Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\nslb37b.tmp\iospecial.ini Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nslb37b.tmp\modern-wizard.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nslb37b.tmp\shortcutlocation Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\nslb37b.tmp\shortcutlocation Generic Write,Read Attributes

Windows API Usage

Category API
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation
Process Shell Execute
  • WriteConsole
Keyboard Access
  • GetAsyncKeyState

Shell Command Execution

WriteConsole: ERROR: Bad archive c:\users\user\downloads\a15fede38bb60402922e0726db152df95e110bae_0000012960

Trending

Most Viewed

Loading...