PUP.MediaGet

Analysis Report

General information

Family Name: PUP.MediaGet
Packers: UPX
Signature status: Self Signed

Known Samples

MD5: 743def049bb61665ebe4b03c3b625f1c
SHA1: 64a6a2700d20062be66f3f7491b681f923863748
SHA256: AB1C50EA8E22B46977540DDF4BCF32CCC7B6522A277ECE9C7D40B62A8BFF7D57
File Size: 7.37 MB, 7370984 bytes
MD5: 53f5e633ce66a614dd7ecf208807a24c
SHA1: 19ca10cc12f8152567781ef9eaa3c1a6cf7a60d2
SHA256: 9C0191ECABD85227E9D40D4455DE3D14C53C5AEC219E0073DE083D6720CB21B1
File Size: 686.59 KB, 686591 bytes
MD5: 5407d3e933ea702edd85c8143814998c
SHA1: b4e60529c7a45512216b5a0e88cbf653e6a1a7f7
SHA256: 59CFDB16C328D75E14E5D14A5F21A6F77B69EBDC8AA4A81299394BD450A51570
File Size: 632.67 KB, 632673 bytes
MD5: ede974c6d3ed331ed58f5b8360615c11
SHA1: 940c5628bc6f93e25cf0763a41b92f7ec1705cf1
SHA256: 59228CA30BCAD5389C265660A251C203F7A09D00E30B19863444AE24F4429A08
File Size: 1.01 MB, 1012376 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has been packed
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments
  • MediaGet installer
  • This installation was built with Inno Setup.
Company Name
  • MediaGet
  • MediaGet LLC
File Description
  • MediaGet installer
  • MediaGet Setup
File Version 1.0
Internal Name mediaget-installer
Legal Copyright Copyright (c) 2011 MediaGet LLC
Original Filename mediaget-installer.exe
Product Name
  • MediaGet
  • mediaget-installer Module
Product Version 1.0

Digital Signatures

Signer Root Status
Media Get LLC Media Get LLC Self Signed

Block Information

Similar Families

  • MediaGet.A

Files Modified

File Attributes
\device\namedpipe\dav rpc service Generic Read,Write Data,Write Attributes,Write extended,Append data
\device\namedpipe\srvsvc Generic Read,Write Data,Write Attributes,Write extended,Append data
\device\namedpipe\wkssvc Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\microsoft\windows\explorer\iconcache_16.db Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\microsoft\windows\explorer\iconcache_idx.db Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-4tv4j.tmp\64a6a2700d20062be66f3f7491b681f923863748_0007370984.tmp Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\explorer\mountpoints2\##10.200.31.10#amas::_labelfromdesktopini RegNtPreCreateKey

Windows API Usage

Category API
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
User Data Access
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
Keyboard Access
  • GetKeyState

Shell Command Execution

"C:\Users\Ekfmquit\AppData\Local\Temp\is-4TV4J.tmp\64a6a2700d20062be66f3f7491b681f923863748_0007370984.tmp" /SL5="$10280,6975602,141312,c:\users\user\downloads\64a6a2700d20062be66f3f7491b681f923863748_0007370984"

Related Posts

Trending

Most Viewed

Loading...