PUP.MSIL.Bulz.LZ

Analysis Report

General information

Family Name: PUP.MSIL.Bulz.LZ
Signature status: No Signature

Known Samples

MD5: 81450307eff875022be66e84cc1f027f
SHA1: 9a8973797a1c8ca82b76e95b055282645f95a8c6
SHA256: A503060FA5A6502AF22766CD0F0C1578CFCD4C9FB1013716005A0E0D546D8CFB
File Size: 593.92 KB, 593920 bytes
MD5: bd2d8fa76a11b1b663e82e63a3bf27dc
SHA1: f91532e4ea869e6d69a7f03110b0119523979f4e
SHA256: D3E54B7282703B52B8137EA4B2ED3F2E79A0013A65130D5E6737D1DD8BF9807D
File Size: 548.86 KB, 548864 bytes
MD5: 3d9b46e66d406ff4b98f47e6bf1d93dd
SHA1: 07f0ffe9257acefb24d459ea6df167145711016d
SHA256: CA4311C44C594583E4427EFA098D9123D9052ACBE6953F3F5CD33E1DAF0278C2
File Size: 721.92 KB, 721920 bytes
MD5: 0c1d55aef88badfca9e743440cb59478
SHA1: a555a3a9a555e48aba593e86a2056ed346cedc74
SHA256: ADF069D3F4EB133E7723238D7F9876B74C0217646D2C71711E6D7CBC429CF358
File Size: 594.43 KB, 594432 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version 1.0.0.0
Company Name
  • Ascora GmbH
  • FonePaw
  • Movavi
  • TuneBoto
File Description
  • FonePaw Android Data Recovery
  • Movavi Video Editor Plus 22.3.0
  • SSDFresh
  • Tuneboto Amazon Video Downloader
File Version
  • 22.3.0.0
  • 5.2.0.110380
  • 1.5.0
  • 1.0.0.0
Internal Name
  • FonePaw Android Data Recovery
  • Movavi Video Editor Plus
  • SSDFresh.exe
  • Tuneboto Amazon Video Downloader
Legal Copyright
  • Copyright (C) 2004 - 2022 movavi.com All rights reserved
  • Copyright (C) 2014 - 2022 FonePaw. All rights reserved.
  • Copyright ©
  • Copyright © 2021 Tuneboto Amazon Video Downloader
Original Filename
  • FonePaw Android Data Recovery.exe
  • SSDFresh.exe
  • VideoEditorPlus.exe
Product Name
  • FonePaw Android Data Recovery
  • Movavi Video Editor Plus 2022
  • SSDFresh
  • Tuneboto Amazon Video Downloader
Product Version
  • 22.3.0.0
  • 5.2.0.110380
  • 1.5.0.367
  • 1.0.0.0
Squirrel Aware Version 1
Thin App Build Date Time
  • 20211215 034530
  • 20220111 091834
  • 20220530 210333
  • 20220531 233509
Thin App License
  • DrZero
Thin App Version
  • 2111.0.0-18970417

File Traits

  • HighEntropy
  • ntdll
  • WriteProcessMemory
  • x86

Block Information

Total Blocks: 687
Potentially Malicious Blocks: 2
Whitelisted Blocks: 685
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 1 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 1 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 1 0 0 1 2 3 1 0 1 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 2 3 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 1 0 0 0 0 2 2 1 0 0 0 0 0 1 1 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 1 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.BNE
  • MSIL.Bulz.LZ

Windows API Usage

Category API
Anti Debug
  • NtQuerySystemInformation

Trending

Most Viewed

Loading...