Threat Database Hacktool PUP.Keygen.T

PUP.Keygen.T

By CagedTech in Hacktool

Threat Scorecard

Popularity Rank: 11,224
Threat Level: 10 % (Normal)
Infected Computers: 1,127
First Seen: February 1, 2011
Last Seen: May 10, 2026
OS(es) Affected: Windows

Aliases

15 security vendors flagged this file as malicious.

Antivirus Vendor Detection
Ikarus Trojan-Downloader.Murlo
AhnLab-V3 Downloader/Win32.Murlo
Sophos White Smoke
AntiVir TR/Dldr.Murlo.lbc
McAfee Artemis!2BC02BD91EFF
Panda Trj/CI.A
AVG Dropper.Generic3.JOC
McAfee-GW-Edition Artemis!B764218803F9
BitDefender Trojan.Generic.KDV.119262
Kaspersky IM-Worm.Win32.Yahos.mp
Avast Win32:Trojan-gen
K7AntiVirus Riskware
McAfee W32/Sdbot.bfr!a
Panda Suspicious file
AVG BackDoor.Agent.AJSD

File System Details

PUP.Keygen.T may create the following file(s):
# File Name MD5 Detections
1. nvsvc32.exe b764218803f9d1259be73aaac76e8789 2
2. WSZugo.exe 2bc02bd91effe9ff160ed23f5ed975de 1
More files

Analysis Report

General information

Family Name: PUP.Keygen.T
Packers: UPX
Signature status: No Signature

Known Samples

MD5: b2e1e9835a9ce49138205763c7195908
SHA1: 9656f0eb05a32642aa0db7beebca23472f5c0d7a
SHA256: C173D29A713E92373AEAC4DAB3953B75A945B68CCD1BA1CCF299720F1CD9D977
File Size: 208.13 KB, 208131 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has been packed
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name Bidjan Reclame & Computerservice
File Description Bidjan Reclame & Computerservice
File Version 3.0
Internal Name PATCH
Legal Copyright © 2002 Bidjan Reclame & Computerservice
Legal Trademarks Bidjan Reclame & Computerservice
Original Filename PATCH.EXE
Product Name Patch Application
Product Version 3.0

File Traits

  • .UPX
  • 00 section
  • 2+ executable sections
  • HighEntropy
  • packed
  • x86

Block Information

Total Blocks: 505
Potentially Malicious Blocks: 4
Whitelisted Blocks: 499
Unknown Blocks: 2

Visual Map

x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ?
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Rayra.A

Windows API Usage

Category API
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation

Related Posts

Trending

Most Viewed

Loading...