PUP.Kugou.A

Analysis Report

General information

Family Name: PUP.Kugou.A
Signature status: Self Signed

Known Samples

MD5: ab9ae6a664282b24922dd94e75bf6f23
SHA1: ffc1a70d23a8d42a347b262fd8f488921348ac95
SHA256: 42EE237BC1008B4C80F01C9C9D6F2FE2E278F21B10716413F9703E99DF9CBFB0
File Size: 2.21 MB, 2209472 bytes
MD5: 00f0d21595fee3791cbf6e4aa7c71202
SHA1: 2291baaf23919f7a18cfa8d7412e2b2e0f81f9ef
SHA256: 5E13A320C0C4D2ACC0BF7A591CD4F554FF5A27EBE762BF2E92EAD5FC1031FE47
File Size: 5.90 MB, 5900936 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name 酷狗音乐
File Description 酷狗音乐 Uninstall
File Version
  • 9.1.44.23567
  • 8.3.95.21568
Legal Copyright 酷狗音乐
Product Name 酷狗音乐

Digital Signatures

Signer Root Status
Guangzhou KuGou Computer Technology Co., Ltd. Symantec Class 3 SHA256 Code Signing CA Self Signed

File Traits

  • dll
  • HighEntropy
  • x86

Files Modified

File Attributes
c:\users\user\appdata\local\temp\nsba4d7.tmp\border.png Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsba4d7.tmp\close.png Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsba4d7.tmp\isx.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsba4d7.tmp\kgskin.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsba4d7.tmp\nsdialogs.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsba4d7.tmp\progressbar.png Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsba4d7.tmp\radio0.png Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsba4d7.tmp\radio1.png Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsba4d7.tmp\song.png Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsba4d7.tmp\system.dll Generic Write,Read Attributes
Show More
c:\users\user\appdata\local\temp\nsba4d7.tmp\unbg1.jpg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsba4d7.tmp\unbg2.jpg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsba4d7.tmp\unbg3.jpg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsba4d7.tmp\uncancel.png Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsba4d7.tmp\uninstall.skn Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsba4d7.tmp\unnext.png Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsba4d7.tmp\unok.png Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsbbf7d.tmp\border.png Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsbbf7d.tmp\close.png Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsbbf7d.tmp\isx.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsbbf7d.tmp\kgskin.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsbbf7d.tmp\nsdialogs.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsbbf7d.tmp\progressbar.png Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsbbf7d.tmp\radio0.png Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsbbf7d.tmp\radio1.png Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsbbf7d.tmp\song.png Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsbbf7d.tmp\svg.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsbbf7d.tmp\system.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsbbf7d.tmp\unbg1.jpg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsbbf7d.tmp\unbg2.jpg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsbbf7d.tmp\unbg3.jpg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsbbf7d.tmp\uncancel.png Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsbbf7d.tmp\uninstall.skn Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsbbf7d.tmp\unnext.png Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsbbf7d.tmp\unok.png Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~nsu.tmp\au_.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144

Registry Modifications

Key::Value Data API Name
HKLM\system\controlset001\control\session manager::pendingfilerenameoperations *1\??\C:\Windows\SystemTemp\MicrosoftEdgeUpdate.exe.old122e4*1\??\C:\Windows\SystemTemp\CopilotUpdate.exe.old12352*1\??\C:\P RegNtPreCreateKey
HKLM\system\controlset001\control\session manager::pendingfilerenameoperations *1\??\C:\Windows\SystemTemp\MicrosoftEdgeUpdate.exe.old122e4*1\??\C:\Windows\SystemTemp\CopilotUpdate.exe.old12352*1\??\C:\P RegNtPreCreateKey
HKLM\system\controlset001\control\session manager::pendingfilerenameoperations *1\??\C:\Windows\SystemTemp\MicrosoftEdgeUpdate.exe.old5af52*1\??\C:\Windows\SystemTemp\CopilotUpdate.exe.old5af62*1\??\C:\P RegNtPreCreateKey

Windows API Usage

Category API
Process Shell Execute
  • CreateProcess
Other Suspicious
  • AdjustTokenPrivileges

Shell Command Execution

"C:\Users\Zpextoud\AppData\Local\Temp\~nsu.tmp\Au_.exe" _?=c:\users\user\downloads\
"C:\Users\Bkpasika\AppData\Local\Temp\~nsu.tmp\Au_.exe" _?=c:\users\user\downloads\

Trending

Most Viewed

Loading...