Threat Database Hacktool PUP.Keygen.MB

PUP.Keygen.MB

By CagedTech in Hacktool

Threat Scorecard

Popularity Rank: 2,894
Threat Level: 10 % (Normal)
Infected Computers: 1,968
First Seen: August 24, 2011
Last Seen: December 28, 2025
OS(es) Affected: Windows

Aliases

15 security vendors flagged this file as malicious.

Antivirus Vendor Detection
Fortinet W32/Palevo.BT!tr
AhnLab-V3 Trojan/Win32.Lethic
Antiy-AVL Trojan/Win32.Inject.gen
AntiVir TR/Gendal.KD.316723.6
Kaspersky Trojan.Win32.Jorik.Lethic.m
NOD32 a variant of Win32/Injector.ITD
K7AntiVirus Trojan
McAfee Generic.dx!bahc
CAT-QuickHeal Trojan.Jorik.Lethic.m
Panda W32/P2PWorm.HO
AVG Dropper.Generic4.ZLP
Fortinet W32/Agent.LKP!tr
Ikarus Virus.Win32.CeeInject
AhnLab-V3 Win-Trojan/Seint.196608.AK
Microsoft VirTool:Win32/CeeInject.Z

File System Details

PUP.Keygen.MB may create the following file(s):
# File Name MD5 Detections
1. aadrive32.exe f0250e261211a0441d10c4394cca42b8 7
2. regsrv64.exe be4229cc4d398ab968854c0c81e40232 1

Analysis Report

General information

Family Name: PUP.Keygen.MB
Packers: ASPack v2.12
Signature status: No Signature

Known Samples

MD5: 3d08e6046b0143b78a36bb10dea8b71c
SHA1: fdb9c69aa1ebb7bc3dc4123540a14fe6e4293689
SHA256: 6D2E7B8F925557B9782100E75D0535E623D2806C5FD3D5A6492F2756EA5A3206
File Size: 31.74 KB, 31744 bytes
MD5: bbcc793527924509facd444e5c089251
SHA1: 97ada8667ccb17e163e6f1aaea34a908dad6cd5d
SHA256: F52913179C53C5F086B974A37101108B226856189EF270DE7991F215F3F5195E
File Size: 30.72 KB, 30720 bytes
MD5: 23273491e5b320dcb3ea33eedc8151db
SHA1: e70dcc2f267f5838376e8cf769e97fb7ee1fed3a
SHA256: 390BF317B8B66AF45838545CB8E9EE6F0A90708E1845D49F2DA8E982F34AF398
File Size: 31.23 KB, 31232 bytes
MD5: d207adfd5440bec50d7422e645e8bfd4
SHA1: a9bdaa0b7f0d92d424a0c1f0848ef9bfd8e322de
SHA256: D3292D524C079621B5C0D79B3C212B6F9F007A51472B9E8BB3ED9810F76EEEE1
File Size: 281.56 KB, 281559 bytes
MD5: c74bb6163966986473f0436b9bd3a728
SHA1: 59cd08e4f783824ec5e2333e211d812bf0fac095
SHA256: 56363B5758B69F267B6F978BCE99C4889D893D562EDC0804B26C04C4BBF89C63
File Size: 69.12 KB, 69120 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has been packed
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name
  • KelSat Presents
  • Microsoft
File Description Brink V1.0 Update3 Plus 5 Trainer
File Version
  • 1.00
  • 1, 0, 0, 0
Internal Name
  • Brink V1.0 Update3 Plus 5 Trainer
  • Win
Legal Copyright KelSat Presents
Original Filename Win.exe
Product Name
  • Brink V1.0 Update3 Plus 5 Trainer
  • Win
Product Version
  • 1.00
  • 1, 0, 0, 0

File Traits

  • .adata
  • .aspack
  • 2+ executable sections
  • ASPack v2.12
  • HighEntropy
  • No Version Info
  • packed
  • PEC2
  • PECompact v2.20
  • WriteProcessMemory
Show More
  • x86

Block Information

Total Blocks: 10
Potentially Malicious Blocks: 1
Whitelisted Blocks: 9
Unknown Blocks: 0

Visual Map

x 0 1 0 0 0 1 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
\device\namedpipe\gmdasllogger Generic Write,Read Attributes

Windows API Usage

Category API
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation
Other Suspicious
  • SetWindowsHookEx

Trending

Most Viewed

Loading...