PUP.MSIL.Brute.BBK

Analysis Report

General information

Family Name: PUP.MSIL.Brute.BBK
Signature status: No Signature

Known Samples

MD5: 3471be5989481a8ecd53d615d8f9acd2
SHA1: 5fd4cc823e8c878efb857b2e5b62bba2a286f0ec
SHA256: 3B478B64442063D2CFA532A8B1D69F77C0207736D85D270B4DEF31233F448B0A
File Size: 585.73 KB, 585728 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Comments 74596ef9 4a97 4ce0 9ff9 6a6e8f0f30e3
Company Name Murray Hurps Software Pty Ltd
File Description Ad Muncher
Guid e9c308bc-fe56-4270-a974-c8f9c1a93925
Legal Copyright Copyright © Murray Hurps Software Pty Ltd
Legal Trademarks 40951764 4999 4bd2 844f 89721aff9fde
Product Name Ad Muncher

File Traits

  • .NET
  • x86

Block Information

Total Blocks: 95
Potentially Malicious Blocks: 29
Whitelisted Blocks: 42
Unknown Blocks: 24

Visual Map

? 0 x ? ? x ? ? x x x x x 0 ? 0 ? x x x x ? 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? x ? ? ? ? ? ? x x x ? ? ? ? x 0 0 x x 0 x 0 x 0 x x 0 0 x x x 0 0 x x 0 0 x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
User Data Access
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Anti Debug
  • NtQuerySystemInformation
Encryption Used
  • BCryptOpenAlgorithmProvider
Other Suspicious
  • AdjustTokenPrivileges
Process Manipulation Evasion
  • NtUnmapViewOfSection
  • ReadProcessMemory
  • VirtualAllocEx
Process Shell Execute
  • CreateProcess

Shell Command Execution

c:\users\user\downloads\5fd4cc823e8c878efb857b2e5b62bba2a286f0ec_0000585728 "c:\users\user\downloads\5fd4cc823e8c878efb857b2e5b62bba2a286f0ec_0000585728"

Related Posts

Trending

Most Viewed

Loading...