PUP.MSIL.Brute.FD

Analysis Report

General information

Family Name: PUP.MSIL.Brute.FD
Signature status: No Signature

Known Samples

MD5: e2b17e0a69c8d054ba10b94a759c20f3
SHA1: 7d99e4e5db8778a833960436c9a72337b99a3ccc
SHA256: 5E6B47A04DDD0CF5A7F7530337F921EFABEF3238F0080F68E7760F4DAD117B69
File Size: 340.48 KB, 340480 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Assembly Version 1.0.0.1
Company Name Microsoft
File Description HaspSupport
File Version 1.0.0.1
Internal Name HaspSupport.exe
Legal Copyright Copyright © Microsoft 2016
Original Filename HaspSupport.exe
Product Name HaspSupport
Product Version 1.0.0.1

File Traits

  • .NET
  • RijndaelManaged
  • x86

Block Information

Total Blocks: 278
Potentially Malicious Blocks: 271
Whitelisted Blocks: 4
Unknown Blocks: 3

Visual Map

x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x ? x x x x x x x x x x 0 x ? x 0 x x x ? 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Brute.FD

Windows API Usage

Category API
User Data Access
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Encryption Used
  • BCryptOpenAlgorithmProvider
Other Suspicious
  • AdjustTokenPrivileges

Trending

Most Viewed

Loading...