PUP.MSIL.Brute.AAF

The detection of PUP.MSIL.Brute.AAF on your system indicates the presence of a potentially unwanted program (PUP) that may compromise your computer's security and performance. It is essential to understand the nature of this threat and take immediate action to remove it to prevent potential harm.

What Is PUP.MSIL.Brute.AAF?

PUP.MSIL.Brute.AAF is a type of potentially unwanted program that can be installed on your computer without your knowledge or consent. It may be bundled with other software or downloaded from untrusted sources. PUPs like PUP.MSIL.Brute.AAF can cause a range of problems, including slowing down your computer, displaying unwanted advertisements, and potentially leading to more severe malware infections.

How PUP.MSIL.Brute.AAF Operates

Once installed, PUP.MSIL.Brute.AAF can operate in the background, consuming system resources and potentially communicating with its creators or other malicious entities. It may also attempt to collect sensitive information, such as browsing history or personal data, which can be used for malicious purposes. PUPs like PUP.MSIL.Brute.AAF can be challenging to detect and remove, as they often disguise themselves as legitimate programs or system files.

Symptoms of Infection

If your computer is infected with PUP.MSIL.Brute.AAF, you may notice a range of symptoms, including slow system performance, unwanted pop-ups or advertisements, and unexpected changes to your browser settings or homepage. You may also experience crashes, freezes, or other system instability issues. In some cases, you may not notice any symptoms at all, which is why regular system scans and monitoring are essential for detecting and removing PUPs like PUP.MSIL.Brute.AAF.

How to Remove PUP.MSIL.Brute.AAF

  1. Boot your computer in Safe Mode with Networking to prevent PUP.MSIL.Brute.AAF from loading and to allow for a more effective removal process.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove PUP.MSIL.Brute.AAF and any related malware.
  3. Uninstall any suspicious programs or applications that may be related to PUP.MSIL.Brute.AAF.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any unwanted extensions or add-ons.
  5. Reboot your computer and perform a follow-up scan to ensure that PUP.MSIL.Brute.AAF has been completely removed.

Conclusion

Removing PUP.MSIL.Brute.AAF from your system is crucial to preventing potential harm and maintaining your computer's security and performance. By following the steps outlined above and taking proactive measures to protect your system, you can help prevent future PUP infections and keep your computer running smoothly. Remember to always be cautious when downloading software or clicking on links, and to regularly scan your system for malware to stay safe online.

Analysis Report

General information

Family Name: PUP.MSIL.Brute.AAF
Packers: UPX
Signature status: Self Signed

Known Samples

MD5: d6a4f5d35ce34617010148603fede053
SHA1: b23f98f5b60fbbde17d3aaf90fdcb706fdf7c1e8
SHA256: 808020E9CD984F4D1EDB64010E65D7D9B229B46BC6F1C146AB2554F26359F182
File Size: 492.90 KB, 492896 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has been packed
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name GOG Sp. z o.o.
File Description Sapphire Safari
File Version 2.0.0.2
Internal Name GOG Galaxy - Game Installer.exe
Legal Copyright (C) GOG Sp. z o.o. 2020
Product Name Sapphire Safari
Product Version 2.0.0.2

Digital Signatures

Signer Root Status
GOG sp. z o.o GOG sp. z o.o Self Signed

File Traits

  • HighEntropy
  • Installer Version
  • packed
  • x86

Block Information

Total Blocks: 3,277
Potentially Malicious Blocks: 285
Whitelisted Blocks: 2,992
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 0 0 x x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 x x x x x x x x x x x x x x x 0 0 0 0 0 0 0 x x x x x 0 x x x x x x x x x x x x x x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x 0 0 x x x x x 0 0 x x x 0 0 x x 0 0 x 0 0 0 0 0 0 x 0 x x x x 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 x x 0 0 x 0 0 0 x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x 0 0 x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 x x x x 0 0 0 0 0 x x x x x x x x x x x x x x x x x 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 x x x x x x x x x x x x x x x x x x x x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x x x 0 0 0 0 0 x x x x 0 0 x 0 0 x x 0 0 0 x x 0 0 x 0 0 0 0 0 0 0 0 x 0 0 0 0 x x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x x x x x 0 x x x x x x x x 0 x 0 x x x x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x 1 0 x x 0 x x 0 x 0 x x 0 0 0 0 x 0 0 0 0 x x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 0 0 0 x x 0 0 0 0 x x 0 0 0 x x x x x x x x x 0 x 0 0 x x x x 0 x x x x x x x x x x x 0 x x 0 0 x 0 x x x 0 x 0 0 0 0 x 0 0 0 x x 0 0 0 0 x x 0 x 0 0 0 0 0 0 x x x x x x x 0 0 0 0 x 0 x 0 0 0 0 0 0 x x x 0 0 0 0 0 x 0 0 0 x x x 0 0 0 0 0 x x 0 0 0 0 0 x 0 x x 0 0 x 0 0 x 0 0 0 0 0 0 0 x x 0 0 0 x x x 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 1 1 1 0 0 0 1 0 0 0 1 0 1 0 0 0 0 1 1 1 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 1 0 1 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.LX
  • MSIL.Brute.AAC
  • MSIL.Brute.AAF

Files Modified

File Attributes
c:\programdata\gog.com\galaxy\logs\installerbootstrapper.log Generic Write,Read Attributes
c:\users\user\appdata\local\temp\galaxyinstaller_kpput\de\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_kpput\es-mx\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_kpput\es\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_kpput\fr\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_kpput\galaxyinstaller.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_kpput\galaxyinstaller.exe.config Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_kpput\icon.ico Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_kpput\icon.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_kpput\it\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
Show More
c:\users\user\appdata\local\temp\galaxyinstaller_kpput\ja\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_kpput\ko\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_kpput\payload.base64 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\galaxyinstaller_kpput\pl\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_kpput\pt-br\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_kpput\ru\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_kpput\zh-hant\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\galaxyinstaller_kpput\zh\galaxywebinstaller.resources.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\microsoft\windows\recent\automaticdestinations\5f7b5f1e01b83767.automaticdestinations-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\microsoft\windows\recent\automaticdestinations\f01b4d95cf55d32a.automaticdestinations-ms Generic Read,Write Data,Write Attributes,Write extended,Append data

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 鲌ȁ獖}eꙥžЂ엦1¶i ꙥžrr֢vꙥž RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 Lk# �v����(�*J*�h1�1HO@V�A��G�IH[u_�zh�rk�qq�Xvy�w�n{b��P��������6����� [�m�Ù��]�����$�8წ���&M�=�SB1_T�Vw���%�������AE��D��&��$���L RegNtPreCreateKey
Show More
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 Mk- �v����(�*J*�h0P%1�1HO@V�A��G�IH[u\te_�zh�rk�qq�Xvy�w�n{b��P��x���7�M�������6�����j�� [�m�Ù��]��IV����$�8წ���&M�(!�^��j��=�SB1_T�Vw�`�V��3��%�������AE�� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 Nk. �v����(�*J*�h0P%1�1HO@V�A��G�IH[u\te_�zh�rk�qq�Xvy�w�n{b��P��x���7�M�������6�������j�� [�m�Ù��]��IV����$�8წ���&M�(!�^��j��=�SB1_T�Vw�`�V��3��%�������A RegNtPreCreateKey

Windows API Usage

Category API
Network Urlomon
  • URLDownloadToFile
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
User Data Access
  • GetComputerNameEx
  • GetUserObjectInformation
Process Manipulation Evasion
  • NtUnmapViewOfSection
  • ReadProcessMemory
Process Shell Execute
  • CreateProcess
  • ShellExecuteEx
Syscall Use
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtDuplicateObject
Show More
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN

Shell Command Execution

C:\Users\Flhtrwgb\AppData\Local\Temp\GalaxyInstaller_kpPut\GalaxyInstaller.exe "C:\Users\Flhtrwgb\AppData\Local\Temp\GalaxyInstaller_kpPut\GalaxyInstaller.exe" 1804860967 "Sapphire Safari"
(NULL) C:\Users\Flhtrwgb\AppData\Local\Temp\GalaxyInstaller_kpPut\GalaxyInstaller.exe 1804860967 "Sapphire Safari"

Related Posts

Trending

Most Viewed

Loading...