PUP.MediaGet.B

Analysis Report

General information

Family Name: PUP.MediaGet.B
Signature status: Hash Mismatch

Known Samples

MD5: 1cd47553cb6c7504f9804c9690c5b506
SHA1: b72e1ffc6ee5bdb53405848fb86711680e045d07
SHA256: 5C3C0CDBBFBEAEE6AD11D5187C91568A9AF24ED3DE351A6EB6746DE0C78D64E3
File Size: 4.81 MB, 4810240 bytes
MD5: 3c4328770b8dc1a0b6487c4cf46d9680
SHA1: b221fa9148c00e5c7ff514a24f0ae92701fa3138
SHA256: 79AC4DE1CBE4484D23D5B93CD269E7690076B29EC994E27ADF7ED73F6FFCFBDC
File Size: 4.65 MB, 4649423 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments PixelSee Player Installer
Company Name SIA Circle Solutions
File Description PixelSee Player Installer
File Version
  • 14.0.0.0
  • 1.0
Internal Name pixelsee
Legal Copyright Copyright � 2022-2023 SIA Circle Solutions
Original Filename pixelsee
Private Build 0
Product Name PixelSee
Product Version
  • 14.0.0.0
  • 1.0

Digital Signatures

Signer Root Status
SIA Circle Solutions Sectigo Public Code Signing Root R46 Hash Mismatch

File Traits

  • big overlay
  • HighEntropy
  • Installer Version
  • x86

Block Information

Total Blocks: 8,095
Potentially Malicious Blocks: 1,922
Whitelisted Blocks: 6,102
Unknown Blocks: 71

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x x x x x x x x x x 0 0 x x x x 0 0 x x x 0 0 0 x 0 0 0 0 x 0 0 0 x 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x x x x x 0 x 0 0 x x 0 0 0 0 0 x x x x 0 x x x 0 0 0 0 x x 0 x x 0 0 0 x x 0 0 x 0 0 0 0 x x x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 x 0 x x 0 x x x 0 0 x x x x x x 0 x 0 0 x 0 x x x 0 0 x 0 0 0 x x 0 x 0 x x 0 0 x 0 x x 0 0 x x x x 0 x x 0 x 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 x x x 0 0 x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x 0 0 0 0 0 x 0 0 0 0 x 1 1 1 0 0 x 0 x 0 0 0 0 0 0 0 0 x x 0 x x x 0 x 0 0 0 0 x x x 0 0 0 x 0 0 x 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 x 0 0 x x x x x x x x x x x 0 0 x x 0 0 x 0 x 0 0 0 0 x x 0 0 0 0 0 0 x x 0 0 x x 0 0 0 0 0 0 0 0 0 x x x x x 0 x x x 0 0 x 0 0 0 x x x 0 0 0 0 0 0 x x 1 1 1 1 1 1 0 x 0 0 x x 0 x x x x x x 0 0 0 0 0 x 0 0 0 x x 0 0 x x x 0 0 0 x 0 x 0 0 0 x 0 0 0 0 0 0 x x 0 0 0 0 x x 0 x x 0 x x x 0 0 x x x 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 x 0 0 0 x 0 0 x x 0 0 1 0 0 0 0 0 0 0 0 0 x x 0 x 0 x 0 0 0 0 x x x x x x 0 0 0 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 x x 0 x x 0 0 0 1 x x x x 0 0 x x x x 0 x x 0 x x x x 0 0 0 0 0 0 x 0 0 x x 0 0 0 0 0 0 0 0 0 x x x 0 0 x x x 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x x x x 0 0 0 0 0 0 0 0 0 x x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 x x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 x 0 0 x x 0 0 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 x 0 x 0 0 0 0 x 0 0 x 0 0 x 0 x 0 0 0 x 0 0 x 0 x 0 0 x x 0 x 0 x x 0 x 0 x x 0 0 x 0 0 0 0 x 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 x x x x 0 0 0 0 0 x x 0 0 0 x 0 x x 0 0 0 x 0 0 0 0 x 0 0 0 0 0 0 0 x x x 0 x x x x 0 0 0 x 0 0 x 0 0 x 0 0 0 0 x 0 0 0 x x x x 0 0 0 0 x 0 0 0 0 0 0 x x x x x x x 0 0 0 0 0 x 0 0 x 0 x x 0 x 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 x 0 x 0 0 x 0 x x x 0 0 x 0 x 0 0 x 0 0 x x 0 x x x 0 x 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 x x x 0 0 0 x 0 x 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x 0 0 0 0 0 0 0 0 0 x 0 0 x x x 0 0 0 x x 0 0 0 0 0 x x 0 0 x x x 0 0 0 0 x 0 x x x 0 0 0 0 x 0 0 x 0 0 0 x 0 0 x 0 x 0 0 0 0 0 x x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 x x 0 x 0 x x 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 x 0 0 0 0 0 0 x x 0 0 0 x x 0 0 0 0 0 x x x x x 0 0 0 x x x 0 x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 x x 0 x 0 0 x 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 x 0 0 0 0 x x x x 0 x 0 x x x 0 x 0 0 0 0 x x x x 0 x x x 0 x 0 0 x x 0 0 0 0 0 0 0 x 0 0 0 x x 0 0 0 0 0 0 0 0 0 x x x 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? x x 0 0 0 x x x x 0 0 0 ? ? x ? x x ? ? 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 1 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 x 0 0 0 0 0 x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 x 0 x 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 x 0 0 0 0 0 0 0 0 x x x x 0 0 0 x x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x 0 0 x 0 0 x 0 0 0 0 0 0 0 x x x x x 0 0 0 0 0 x 0 x 0 0 x 0 0 x x 0 0 x x 0 0 0 0 0 0 0 x x 0 0 0 0 x 0 0 x 0 0 0 0 x x x 0 0 0 0 x x x 0 x x x 0 0 x 0 x 0 0 0 0 x x 0 0 x x x 0 x x 0 0 x x 0 x x x 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 x x x x x x 0 0 0 0 x x x x 0 0 0 x x 0 0 0 x x 0 0 x x x 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 x x 0 0 0 x 0 0 0 x 0 x x x x x x x x x x x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MediaGet.B

Registry Modifications

Key::Value Data API Name
HKCU\software\media get llc\mediaget2-systemscope\mediaget_info::hasdownloadedupdate false RegNtPreCreateKey

Windows API Usage

Category API
Service Control
  • OpenSCManager
  • OpenService
Network Winsock2
  • WSAStartup

Trending

Most Viewed

Loading...