PUP.MSIL.DllInject.TA

Analysis Report

General information

Family Name: PUP.MSIL.DllInject.TA
Signature status: No Signature

Known Samples

MD5: 665609805ed314de215feb23ca213201
SHA1: b302d23513d568fd55ef642ebde0ce44da30c921
SHA256: B12EF7152E59F2E17C7A71B4735CB78DAF3DA2C1AF5BE295181DCB249F620AEC
File Size: 33.79 KB, 33792 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Assembly Version 1.0.0.0
Company Name Microsoft
File Description ManagedMemoryManipulation
File Version 1.0.0.0
Internal Name ManagedMemoryManipulation.dll
Legal Copyright Copyright © Microsoft 2011
Original Filename ManagedMemoryManipulation.dll
Product Name ManagedMemoryManipulation
Product Version 1.0.0.0

File Traits

  • .NET
  • dll
  • WriteProcessMemory
  • x86

Block Information

Total Blocks: 190
Potentially Malicious Blocks: 104
Whitelisted Blocks: 78
Unknown Blocks: 8

Visual Map

0 0 0 0 x x x x x x 0 x 0 0 x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x x x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x x 0 0 0 0 0 0 x 0 0 0 x x x x x x 0 x x 0 x x x x x 0 0 x 0 x x 0 0 0 0 x x 0 0 x 0 x x 0 0 x x x 0 0 x x x x x 0 0 x x ? ? ? 0 ? ? ? ? ? 0 x x x x x x x x x x x x x 0 x x x x x x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x x x x 0 x 0 x x x x 0 0 x x 0 x x x 0 0 x 0 x x x x x x 0 x 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.DllInject.TA

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
Show More
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • UNKNOWN

Trending

Most Viewed

Loading...