PUP.Koal

Analysis Report

General information

Family Name: PUP.Koal
Signature status: Root Not Trusted

Known Samples

MD5: 07f27950a9ad26fed204d4dd8df70ec8
SHA1: 8c5494c0bb24806e18cdf4c45bf6cbc1f54846a8
SHA256: D226A568444644E27FD442FAD98CCCC757CDE26939B6328A82B4A0BB72AAE8DC
File Size: 2.42 MB, 2420396 bytes
MD5: d8140940b71198f3133b4a8b6346a4a2
SHA1: b3619801834117904534979d1716ddd47ba37a06
SHA256: 7762975EE89D9828CC69FADB657360977DD2399C37B8DC54947924CCF8462171
File Size: 73.66 KB, 73664 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name Microsoft Corporation
File Description
  • ECM Certificate Manager
  • 格尔证书客户端配置工具 v0.9.8
File Version
  • 6.1.7600.16385 (win7_rtm.090713-1255)
  • 0, 9, 8, 0
Internal Name
  • CERTMGR.EXE
  • ConfigTools
Legal Copyright
  • © Microsoft Corporation. All rights reserved.
  • 上海格尔软件股份公司 版权所有 (C) 1998~2013
Original Filename
  • CERTMGR.EXE
  • ConfigTools.EXE
Product Name
  • ConfigTools 应用程序
  • Microsoft® Windows® Operating System
Product Version
  • 6.1.7600.16385
  • 0, 9, 8, 0
Special Build 102

Digital Signatures

Signer Root Status
上海格尔软件股份有限公司 Class 3 Public Primary Certification Authority Root Not Trusted

File Traits

  • big overlay
  • x86

Block Information

Total Blocks: 133
Potentially Malicious Blocks: 0
Whitelisted Blocks: 133
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 2 1 1 0 0 1 0 0 0 0 0 0 0 0 0 0 2 3 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.ACB
  • Agent.IFSB
  • Agent.XFG
  • Agent.XXS
  • Autorun.SA
Show More
  • Kryptik.DGE

Windows API Usage

Category API
Cert Store Read
  • CertEnumCertificatesInStore
  • CertOpenStore

Trending

Most Viewed

Loading...